|
Message-ID: <1254955020.94867.1303332352648.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com> Date: Wed, 20 Apr 2011 16:45:52 -0400 (EDT) From: Josh Bressers <bressers@...hat.com> To: oss-security@...ts.openwall.com Cc: Richard Hughes <rhughes@...hat.com>, Ray Strode <rstrode@...hat.com>, lsof@...ata.co.uk, "Steven M. Christey" <coley@...us.mitre.org> Subject: Re: CVE Request -- gnome-desktop3: Switching users dialog does not lock the screen for the original user account Please use CVE-2011-1596 Thanks. -- JB ----- Original Message ----- > Hello Josh, Steve, vendors, > > it has been reported that using of Gnome upon using of "Switch user" > dialog, log in into a > new user account (user2), logout of new user account (user2) the > desktop is returned to the > original user account (for user1) without prompting for a password. A > locally proximate > attacker could use this flaw to access resources, which should be > otherwise protected > by authentication. > > Original report: > [1] https://bugzilla.redhat.com/show_bug.cgi?id=697199 > > Upstream bug report: > [2] https://bugzilla.gnome.org/show_bug.cgi?id=648234 > > Could you allocate a CVE id for this? > > Thanks && Regards, Jan. > -- > Jan iankko Lieskovsky / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.