[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon
Fantu
1912060 at bugs.launchpad.net
Mon Jan 25 22:48:01 UTC 2021
@Joshua Peisach: On ubuntu version released the only way to update is SRU: https://wiki.ubuntu.com/StableReleaseUpdates
Do a backport (for example for focal in focal-backports) will require that user enable backports (if not) and install it; user that don't know and do it will not have the fix.
The patch have same changes to code and only changelog changes, version of the caribou patched is also the same and there should be without risk, anyway I tested build in focal installed and checked that issue is not reproducible anymore (and no regression is showed); a fast test in groovy it would still be better although it is very unlikely that there are differences on result.
--
You received this bug notification because you are a member of Ubuntu
Sponsors Team, which is subscribed to the bug report.
https://bugs.launchpad.net/bugs/1912060
Title:
[SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
cause security issue for cinnamon
Status in caribou package in Ubuntu:
Fix Released
Status in caribou source package in Focal:
In Progress
Status in caribou source package in Groovy:
In Progress
Status in caribou source package in Hirsute:
Fix Released
Status in caribou package in Debian:
Unknown
Bug description:
[Impact]
There is a regression after solving CVE-2020-25712 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25712) in xserver (https://gitlab.freedesktop.org/xorg/xserver/-/commit/87c64fc5b0db9f62f4e361444f4b60501ebf67b9) that make caribou crash pressing ē.
In cinnamon-screensaver (>=4.2 where integrated the virtual keyboard)
crash of caribou cause also screensaver crash and make possible access
without insert the correct password, this introduced a security issue.
[Test Case]
In cinnamon-screensaver (>=4.2) pressing ē (after long press on e) in virtual keyboard (button at the bottom of the screen in the center) make caribou (and the screensaver) crash and access without insert the correct password.
[Where problems could occur]
The following versions of ubuntu are affected by the security caused by caribou crash of this issue:
- Focal (cinnamon 4.4)
- Groovy (cinnamon 4.6)
- Hirsute (bug solved with 0.4.21-7.1)
The patch attached in comment #10 (for Focal) have the same changes of 0.4.21-7.1 (debian unstable, debian testing and Hirsute) and same patches are used also in some other distros that already applied the fix faster (as security issue) and 1 week or more went by without experiencing regressions at the moment.
The patch is already tested in Focal, can be used also in Groovy (only changing focal->groovy).
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions
More information about the Ubuntu-sponsors
mailing list