Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1046839 - (CVE-2013-7221) CVE-2013-7221 gnome-shell: run command dialog visible above screen locker
CVE-2013-7221 gnome-shell: run command dialog visible above screen locker
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20131114,repor...
: Security
Depends On:
Blocks: 1030960
  Show dependency treegraph
 
Reported: 2013-12-27 00:07 EST by Huzaifa S. Sidhpurwala
Modified: 2015-07-31 08:00 EDT (History)
6 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-12-27 21:46:36 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Huzaifa S. Sidhpurwala 2013-12-27 00:07:26 EST
In Fedora 19, the "Enter the Command" dialog box is visible even after you lock the screen, so anyone can write the commands in the box and execute them over a locked screen.

The issue is still to be fixed and tested on Gnome Fedora 18 and 19 machines. KDE version were not found to be affected.

This flaw is split from bug 1030431
Comment 1 Huzaifa S. Sidhpurwala 2013-12-27 00:23:55 EST
Upstream bug: 
https://bugzilla.gnome.org/show_bug.cgi?id=708313

Upstream patch:
https://git.gnome.org/browse/gnome-shell/commit/js/ui/main.js?id=efdf1ff755943fba1f8a9aaeff77daa3ed338088

This issue has been addressed in gnome-shell-3.10.0
Comment 2 Huzaifa S. Sidhpurwala 2013-12-27 00:27:08 EST
The patch for this issue was backported to Fedora-19 via the following commit:

http://pkgs.fedoraproject.org/cgit/gnome-shell.git/commit/?h=f19&id=dfe68f1744ae3235df60a0be7a900b9279c7f5db 

It is available by upgrading to gnome-shell-3.8.4-3.fc19

Fedora-20 ships gnome-shell-3.10.2 and therefore is not affected.
Comment 4 Huzaifa S. Sidhpurwala 2013-12-27 21:46:36 EST
This issue has been assigned CVE-2013-7221 as per:

http://www.openwall.com/lists/oss-security/2013/12/27/8

Note You need to log in before you can comment on or make changes to this bug.