Fedora Account System
Red Hat Associate
Red Hat Customer
It was discovered that the Caribou onscreen keyboard could be made to crash when given certain input values. An attacker could use this to bypass screen-locking applications that support using Caribou as an input mechanism. Reference: https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060
Created caribou tracking bugs for this issue: Affects: epel-7 [bug 1962838] Affects: fedora-all [bug 1962837]
Upstream merge request: https://gitlab.gnome.org/GNOME/caribou/-/merge_requests/3 Upstream fix: https://gitlab.gnome.org/GNOME/caribou/-/commit/d41c8e44b12222a290eaca16703406b113a630c6
Not strictly required from a security perspective, these are related issues/commits that have been ported upstream from Linux Mint: https://gitlab.gnome.org/GNOME/caribou/-/issues/7 https://gitlab.gnome.org/GNOME/caribou/-/commit/76fbd11575f918fc898cb0f5defe07f67c11ec38 https://gitlab.gnome.org/GNOME/caribou/-/merge_requests/5 https://gitlab.gnome.org/GNOME/caribou/-/commit/ba8219ccc67d1d0964fb9ff25125c3be5fb80681
In reply to comment #0: > It was discovered that the Caribou onscreen keyboard could be made to crash > when given certain input values. An attacker could use this to bypass > screen-locking applications that support using Caribou as an input mechanism. Specifically, this was first reported in the on-screen keyboard which runs within the Cinnamon process and uses libcaribou. Pressing ē led to a Cinnamon crash and possible screensaver lock bypass. Cinnamon issue: https://github.com/linuxmint/cinnamon-screensaver/issues/354
It is worth noting that caribou is only shipped with Red Hat Enterprise Linux 7 (caribou-0.4.21) while cinnamon-screensaver is not shipped in Red Hat products.