[PLUG] Security Vulnerability in Xorg Screen Locking

Daniel Hedlund daniel at digitree.org
Thu Jan 19 20:42:27 UTC 2012


On Thu, Jan 19, 2012 at 11:13, Fred James <fredjame at fredjame.cnc.net> wrote:
>
> Tim Bruce - PLUG wrote:
> > Interestingly enough - I just tried this and it didn't work.  I'm running
> > Ubuntu 11.10 and use a "blank screen" for the screen saver.  Maybe that's
> > the difference (rather than running an actual screen saver).
> >
> > Tim
> >
> Doesn't work on screen lock for Mandriva 2008.0 (old, I know ... so
> maybe a new bug?)
> This screen lock uses screen savers

According to Xorg's commit history, it appears the bug has been around
since the end of June and 13 releases were made with the bug.

Based on the thread and other blogs, Fedora 16, Debian Wheezy
("testing"), ArchLinux, Gentoo and probably others are affected.
Ubuntu 11.10 (Oneiric Ocelot) appears to be unaffected.



More information about the PLUG mailing list