dx-packages team mailing list archive
-
dx-packages team
-
Mailing list archive
-
Message #34864
[Bug 1460626] Re: Unity Lockscreen still shows unlocked desktop while shutting down
This bug was fixed in the package indicator-session -
12.10.5+15.10.20150915-0ubuntu1
---------------
indicator-session (12.10.5+15.10.20150915-0ubuntu1) wily; urgency=medium
[ Andrea Azzarone andrea.azzarone@xxxxxxxxxxxxx ]
* Disable shutdown/reboot in the lockscreen. (LP: #1460626)
[ Sebastien Bacher ]
* under unity8 start system-settings instead unity-control-center (LP:
#1489480)
-- Sebastien Bacher <seb128@xxxxxxxxxx> Tue, 15 Sep 2015 07:47:28
+0000
** Changed in: indicator-session (Ubuntu)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of DX
Packages, which is subscribed to indicator-session in Ubuntu.
Matching subscriptions: dx-packages, dx-packages
https://bugs.launchpad.net/bugs/1460626
Title:
Unity Lockscreen still shows unlocked desktop while shutting down
Status in Unity:
In Progress
Status in indicator-session package in Ubuntu:
Fix Released
Status in unity package in Ubuntu:
Fix Released
Bug description:
This was reported and supposedly fixed in
https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1370017, but the
bug is still present in the current Unity version in Trusty. I've
reported it in that bug already, but got ignored, so I'm opening a new
bug about it.
[Impact and Test Case]
Steps to reproduce:
1 - Log into Unity
2 - Open a terminal.
3 - Lock the screen
4 - From the lockscreen, tell the computer to shut down / restart
Expected behavior:
* Session programs are closed while the screen is still locked
* During shutdown, no user interaction is possible
Observed behavior:
* The lockscreen is gone immediately, with the rest of compiz (e.g. window decorations are not present)
* But it's possible to interact with programs that are still running in the session for about 3 seconds
Observed on an updated Trusty machine, running unity version
7.2.5+14.04.20150521.1-0ubuntu1
This bug is a security vulnerability because during those 3 seconds it
could be possible to access and interact with sensitive information.
Yes, it's short, but you could take a picture or even rm -rf / if
there happened to be a root console available.
To manage notifications about this bug go to:
https://bugs.launchpad.net/unity/+bug/1460626/+subscriptions
References