[Bug 1204934] [NEW] Lock screen needs no password when activated by Power Managment

John Convertino electrobs at gmail.com
Thu Jul 25 14:34:25 UTC 2013


*** This bug is a security vulnerability ***

Public security bug reported:

If the screen is locked with simple locker it will lock after 15
minutes, but when prompted for a password hitting any key will result in
the lock screen going away and the desktop revealed. Resulting in no
password needed to access the pc. I have waited the extra 60 seconds at
least, to make sure it locks. Suspend wakeup brings up the lock and it
works fine. User login requires password as normal.

Hardware:
-Lenovo T500 using intel or amd built in card (I've tested with both for giggles)

Software:
-Clean install of Kubuntu 13.04 with beta ppa enabled
-xorg-edgers enabled
-wine ppa enabled
-3.11 rc 2 kernel

** Affects: kubuntu-ppa
     Importance: Undecided
         Status: New

** Information type changed from Private Security to Public Security

** Description changed:

  If the screen is locked with simple locker it will lock after 15
  minutes, but when prompted for a password hitting any key will result in
  the lock screen going away and the desktop revealed. Resulting in no
  password needed to access the pc. I have waited the extra 60 seconds at
- least, to make sure it locks.
- 
+ least, to make sure it locks. Suspend wakeup brings up the lock and it
+ works fine. User login requires password as normal.
  
  Hardware:
  -Lenovo T500 using intel or amd built in card (I've tested with both for giggles)
  
  Software:
  -Clean install of Kubuntu 13.04 with beta ppa enabled
  -xorg-edgers enabled
  -wine ppa enabled
  -3.11 rc 2 kernel

-- 
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to Kubuntu PPA.
https://bugs.launchpad.net/bugs/1204934

Title:
  Lock screen needs no password when activated by Power Managment

To manage notifications about this bug go to:
https://bugs.launchpad.net/kubuntu-ppa/+bug/1204934/+subscriptions




More information about the kubuntu-bugs mailing list