<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>26836</bug_id>
          
          <creation_ts>2012-01-19 18:54:12 +0400</creation_ts>
          <short_desc>CVE-2012-0064: configuration allows xscreensaver bypass</short_desc>
          <delta_ts>2012-01-23 17:25:38 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>xkeyboard-config</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://www.opennet.ru/opennews/art.shtml?num=32844</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>security</keywords>
          <priority>P3</priority>
          <bug_severity>blocker</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Michael Shigorin">mike</reporter>
          <assigned_to name="Valery Inozemtsev">shrek</assigned_to>
          <cc>crux</cc>
    
    <cc>iv</cc>
    
    <cc>ldv</cc>
    
    <cc>led</cc>
    
    <cc>legion</cc>
    
    <cc>sem</cc>
    
    <cc>shrek</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>128400</commentid>
    <comment_count>0</comment_count>
    <who name="Michael Shigorin">mike</who>
    <bug_when>2012-01-19 18:54:12 +0400</bug_when>
    <thetext>В xorg-server 1.11 сделали отладочную фичу, не задокументировали толком и так и отправили в плавание: нажатие Ctrl-Alt-серая* приводит к снятию блокировки без пароля.

Ссылки:
http://gu1.aeroxteam.fr/2012/01/19/bypass-screensaver-locker-program-xorg-111-and-up/
http://www.opennet.ru/opennews/art.shtml?num=32844
http://jajaz.org/?p=353</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>128401</commentid>
    <comment_count>1</comment_count>
    <who name="Michael Shigorin">mike</who>
    <bug_when>2012-01-19 18:55:56 +0400</bug_when>
    <thetext>PS: XF86_Ungrab и XF86_ClearGrab нашлись в /usr/share/X11/xkb/compat/xfree86</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>128403</commentid>
    <comment_count>2</comment_count>
    <who name="Alexey Gladkov">legion</who>
    <bug_when>2012-01-19 19:14:59 +0400</bug_when>
    <thetext>*** Bug 26835 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>128404</commentid>
    <comment_count>3</comment_count>
    <who name="Alexey Gladkov">legion</who>
    <bug_when>2012-01-19 19:18:31 +0400</bug_when>
    <thetext>Согласно полиси это blocker (http://www.altlinux.org/Bug_Severity_Policy#blocker).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>128405</commentid>
    <comment_count>4</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2012-01-19 19:30:23 +0400</bug_when>
    <thetext>Первоисточник: http://openwall.com/lists/oss-security/2012/01/19/1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>128406</commentid>
    <comment_count>5</comment_count>
    <who name="">led</who>
    <bug_when>2012-01-19 19:53:38 +0400</bug_when>
    <thetext>Security vulnerability - в xorg-server. Blocker bug повешен на xkeyboard-config.

Это &quot;чтоб враги не догадались&quot;:)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>128407</commentid>
    <comment_count>6</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2012-01-19 19:55:47 +0400</bug_when>
    <thetext>Proposed fix:
http://lists.x.org/archives/xorg-devel/2012-January/028691.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>128408</commentid>
    <comment_count>7</comment_count>
    <who name="Mikhail Efremov">sem</who>
    <bug_when>2012-01-20 11:03:27 +0400</bug_when>
    <thetext>Пока можно использовать что-то типа этого:
$ cat ~/.Xmodmap 
keycode  63 = KP_Multiply NoSymbol KP_Multiply NoSymbol
keycode  106 = KP_Divide NoSymbol KP_Divide NoSymbol</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>128423</commentid>
    <comment_count>8</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2012-01-20 22:01:17 +0400</bug_when>
    <thetext>Апстрим сегодня выпустил новую версию xkeyboard-config:
http://cgit.freedesktop.org/xkeyboard-config/tag/?id=xkeyboard-config-2.5

В ней есть соответствующий коммит:
http://cgit.freedesktop.org/xkeyboard-config/commit/?id=dc55259e52ef034e568a50beb43a80b3595e49e4

Предлагаю последовать их примеру.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>128448</commentid>
    <comment_count>9</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2012-01-23 17:25:38 +0400</bug_when>
    <thetext>xkeyboard-config-2.5-alt1 уже в Сизифе.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>