Hide Forgot
It was discovered that the Caribou onscreen keyboard could be made to crash when given certain input values. An attacker could use this to bypass screen-locking applications that support using Caribou as an input mechanism. Reference: https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060
Created caribou tracking bugs for this issue: Affects: epel-7 [bug 1962838] Affects: fedora-all [bug 1962837]
Upstream merge request: https://gitlab.gnome.org/GNOME/caribou/-/merge_requests/3 Upstream fix: https://gitlab.gnome.org/GNOME/caribou/-/commit/d41c8e44b12222a290eaca16703406b113a630c6
Not strictly required from a security perspective, these are related issues/commits that have been ported upstream from Linux Mint: https://gitlab.gnome.org/GNOME/caribou/-/issues/7 https://gitlab.gnome.org/GNOME/caribou/-/commit/76fbd11575f918fc898cb0f5defe07f67c11ec38 https://gitlab.gnome.org/GNOME/caribou/-/merge_requests/5 https://gitlab.gnome.org/GNOME/caribou/-/commit/ba8219ccc67d1d0964fb9ff25125c3be5fb80681
In reply to comment #0: > It was discovered that the Caribou onscreen keyboard could be made to crash > when given certain input values. An attacker could use this to bypass > screen-locking applications that support using Caribou as an input mechanism. Specifically, this was first reported in the on-screen keyboard which runs within the Cinnamon process and uses libcaribou. Pressing ē led to a Cinnamon crash and possible screensaver lock bypass. Cinnamon issue: https://github.com/linuxmint/cinnamon-screensaver/issues/354
It is worth noting that caribou is only shipped with Red Hat Enterprise Linux 7 (caribou-0.4.21) while cinnamon-screensaver is not shipped in Red Hat products.