Bug 900031 (CVE-2014-7300) - VUL-0: CVE-2014-7300: gnome-shell: lockscreen bypass with printscreen key
Summary: VUL-0: CVE-2014-7300: gnome-shell: lockscreen bypass with printscreen key
Status: RESOLVED FIXED
Alias: CVE-2014-7300
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Minor
Target Milestone: ---
Assignee: Chao Xiong
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/108953/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-10-07 07:33 UTC by Sebastian Krahmer
Modified: 2016-04-27 20:31 UTC (History)
8 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Frederic Crozat 2014-10-07 07:52:57 UTC
upstream bug report: https://bugzilla.gnome.org/show_bug.cgi?id=737456

SLE12 (and openSUSE 13.1) are vulnerable too BTW, didn't test older openSUSE versions, probably vulnerable too
Comment 2 Dominique Leuenberger 2014-10-07 08:09:19 UTC
For Factory, 13.2 we can likely just wait for gnome-shell 3.14.1 coming next week (scheduled).

For 13.1 and SLE we ned to backport... I sugest to wait until upstream actually settles on the fix (interesting discussions). Funnily, my machine was too dast... Couln't get it to crash :)
Comment 3 Dominique Leuenberger 2014-10-20 19:56:38 UTC
Fix in openSUSE 13.2 part of GNOME 3.14.1
for openSUSE 13.1, gnome-settings-daemon has been submitted (incident 257810 )
Comment 4 Frederic Crozat 2014-10-21 09:21:16 UTC
Carl, could you take care of this change for SLE12 ?

Thanks !
Comment 5 Swamp Workflow Management 2014-11-03 12:05:09 UTC
openSUSE-SU-2014:1348-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 900031
CVE References: CVE-2014-7300
Sources used:
openSUSE 13.1 (src):    gnome-settings-daemon-3.10.3-24.1
Comment 8 Chao Xiong 2014-11-24 11:59:36 UTC
Maintainence request: https://build.suse.de/request/show/46584

Original patch see bgo#737456, slight modification is made.

Details:
Fix by forbidding print screen in lock screen.

PS: In bgo#737456, there are two patches, the other handles the "oom-killer" issue by preventing simutaneous screenshots.
Comment 17 Swamp Workflow Management 2015-03-18 07:05:10 UTC
SUSE-SU-2015:0515-1: An update that solves one vulnerability and has one errata is now available.

Category: security (moderate)
Bug References: 900031,905158
CVE References: CVE-2014-7300
Sources used:
SUSE Linux Enterprise Software Development Kit 12 (src):    gnome-settings-daemon-3.10.2-20.1
SUSE Linux Enterprise Server 12 (src):    gnome-settings-daemon-3.10.2-20.1
SUSE Linux Enterprise Desktop 12 (src):    gnome-settings-daemon-3.10.2-20.1