GNOME Bugzilla – Bug 609337
CVE-2010-0414 gnome-screensaver: loses its unlock dialog and keyboard grab sometimes when unplugging monitor
Last modified: 2010-02-08 16:03:24 UTC
Created attachment 153272 [details] [review] Migrate lock dialog and keyboard grab to attached head when they would otherwise get dropped Under certain circumstances it is possible to circumvent the security of screen locking functionality of gnome-screensaver by changing the systems physical monitor configuration. Steps to reproduce: 1) Lock screen 2) Move mouse to removable monitor 3) hit escape key to cancel unlock dialog 4) move mouse to bring up unlock dialog on new head 5) unplug monitor 6) quickly hit keys on the keyboard At this point gnome-screensaver will either crash, or show a black screen. If it shows a black screen then hitting "alt-f2" and then typing "pkill -f gnome-screensaver" will bring you to the session.
Comment on attachment 153272 [details] [review] Migrate lock dialog and keyboard grab to attached head when they would otherwise get dropped http://git.gnome.org/browse/gnome-screensaver/commit/?id=a5f66339be6719c2b8fc478a1d5fc6545297d950 http://git.gnome.org/browse/gnome-screensaver/commit/?id=dcca89b7ab6e1220815af38da246434b2e13fd9f
Downstream report: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-0414