Bug 435773 (CVE-2008-0887)
Summary: | CVE-2008-0887 gnome-screensaver using NIS auth will unlock if NIS goes away | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Alan Matsuoka <alanm> | ||||||||
Component: | vulnerability | Assignee: | jmccann | ||||||||
Status: | CLOSED CURRENTRELEASE | QA Contact: | desktop-bugs <desktop-bugs> | ||||||||
Severity: | high | Docs Contact: | |||||||||
Priority: | high | ||||||||||
Version: | unspecified | CC: | ben.taylor, cschalle, dwa, kreilly, rstrode, tao | ||||||||
Target Milestone: | --- | Keywords: | Security | ||||||||
Target Release: | --- | ||||||||||
Hardware: | All | ||||||||||
OS: | Linux | ||||||||||
Whiteboard: | |||||||||||
Fixed In Version: | 2.18.2-4.fc7 | Doc Type: | Bug Fix | ||||||||
Doc Text: | Story Points: | --- | |||||||||
Clone Of: | Environment: | ||||||||||
Last Closed: | 2008-04-09 05:18:10 UTC | Type: | --- | ||||||||
Regression: | --- | Mount Type: | --- | ||||||||
Documentation: | --- | CRM: | |||||||||
Verified Versions: | Category: | --- | |||||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||||
Embargoed: | |||||||||||
Bug Depends On: | 436521, 436522, 440255, 440256, 440257 | ||||||||||
Bug Blocks: | 246139 | ||||||||||
Attachments: |
|
Description
Alan Matsuoka
2008-03-03 19:57:41 UTC
Created attachment 296671 [details]
screensaver log
Created attachment 297817 [details]
patch for upstream svn / rawhide
This does not appear to affect xscreensaver. I'm not able to reproduce this as described above. It would affect xscreensaver in a slightly different way (but I have not confirmed this). If the network drops between login and the time that the screensaver starts (or anytime it restarts) it won't lock the screen. So it isn't as severe but still probably not what you expect. I just tested this, xscreensaver does still lock the screen. I just tested xscreensaver on Fedora 8 and this is what happens if the network disconnects before xscreensaver starts: xscreensaver -verbose do_ypcall: clnt_call: RPC: Unable to receive; errno = No route to host YPBINDPROC_DOMAIN: Domain not bound do_ypcall: clnt_call: RPC: Unable to receive; errno = No route to host YPBINDPROC_DOMAIN: Domain not bound do_ypcall: clnt_call: RPC: Unable to receive; errno = No route to host YPBINDPROC_DOMAIN: Domain not bound do_ypcall: clnt_call: RPC: Unable to receive; errno = No route to host YPBINDPROC_DOMAIN: Domain not bound do_ypcall: clnt_call: RPC: Unable to receive; errno = No route to host YPBINDPROC_DOMAIN: Domain not bound Could not figure out who the current user is! [exits] So I tried that on RHEL[234]. xscreensaver will start without the network (it does take quite a long time though). If it's already running it will lock the screen fine. *** Bug 437957 has been marked as a duplicate of this bug. *** embargo was agreed as apr02 with vendor-sec; removing embargo. gnome-screensaver-2.18.2-4.fc7 has been submitted as an update for Fedora 7 gnome-screensaver-2.20.0-12.fc8 has been submitted as an update for Fedora 8 gnome-screensaver-2.18.2-4.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report. gnome-screensaver-2.20.0-12.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report. |