Bug 1150444 - locked-screen should not allow visitors to take screenshots
Summary: locked-screen should not allow visitors to take screenshots
Keywords:
Status: CLOSED UPSTREAM
Alias: None
Product: Fedora
Classification: Fedora
Component: gnome-shell
Version: 21
Hardware: Unspecified
OS: Linux
unspecified
high
Target Milestone: ---
Assignee: Owen Taylor
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-10-08 10:32 UTC by Lubos Kocman
Modified: 2014-10-10 13:07 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2014-10-10 13:07:53 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
actual results (461.10 KB, image/png)
2014-10-08 10:32 UTC, Lubos Kocman
no flags Details


Links
System ID Private Priority Status Summary Last Updated
GNOME Bugzilla 737456 0 None None None Never

Description Lubos Kocman 2014-10-08 10:32:07 UTC
Created attachment 944937 [details]
actual results

Description of problem:


Hello,

I just cleaned my keyboard with locked screen and figured out that I've created 50 MB of screenshots.

I don't want to call it a security issue, but if unauthorized person can consume "unlimited" space on /home or in border case /root (which is usually the same filesystem as /) on a "secured" machine and skip any authentication, then it's a kind of a DOS attack.

Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1. have standard gnome3 installation
2. lock your screen
3. hold or tap printscreen key

Actual results:

screenshots are taken and stored in ~/Pictures

Expected results:

nobody should be able to generate such data on a locked machine.

Additional info:

if there is some "DOS" tracker bug for gnome-shell/lock-screen then please add  Bug 1013299 there as well. It could be nice knowledge base for office surprises.

Comment 1 Florian Müllner 2014-10-10 13:07:53 UTC
Fixed upstream, the 3.14.1 release due next week will bring the fix to Fedora


Note You need to log in before you can comment on or make changes to this bug.