[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#911834: mate-screensaver does not lock the screen



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package: mate-screensaver
Version: 1.16.1
Severity: normal
Tags: security


When I run the proprietary software "VMware Workstation", and the HID devices
are captured by a virtual machine console, the screensaver and screen locking mechanism
are not triggered. As soon as I "release" the keyboard and mouse the screensaver is
triggered instantly.

This could pose a securty risk on workstations where virtual machines are administered.

I suppose that the same problem will affect other VMware products such as VMware Remote Console
and VMware Player because they essentially use the same console mechanism.

The machine where this behavior was observed runs on the following software versions:
- - Debian GNU/Linux v. 9.4 (according to /etc/debian_version)
- - Linux Kernel v. 4.9.0-6-amd64 #1 SMP Debian 4.9.88-1+deb9u1 (2018-05-07) x86_64 GNU/Linux
- - libc v. 2.24-11+deb9u3
- - mate-screensaver v. 1.16.1
- - VMware Workstation v. 14.1.2 build-8497320


Mit freundlichen Grüßen / best regards


i.A. Kevin Kairat

Kommunales Gebietsrechenzentrum Koblenz (KGRZ) 
- - Eigenbetrieb der Stadt Koblenz - 
Verwaltungshochhaus Schängel-Center 
Rathauspassage 2
56068 Koblenz

Tel. +49 (0) 261 / 129-1255
Fax +49 (0) 261 / 129-1250
Mail kevin.kairat@stadt.koblenz.de
PGP https://pgp.mit.edu/pks/lookup?op=get&search=0x2B8F9065B687AB48
Internet: www.koblenz.de
- ------------------------
Sitz des Eigenbetriebes: Koblenz
Registergericht: Amtsgericht Koblenz, HRA 4389
USt-ID der Stadtverwaltung Koblenz: DE148721830
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEj3nFbldoWRLpFYKQK4+QZbaHq0gFAlvRjV4ACgkQK4+QZbaH
q0gmdw/+PY1usgLM+v/K7TGmlSeYVHNzwvcB2hqTlCi8P2K7npGH05fEoyIxTKrJ
0ccJ3YCmLAOJ++PgBxz8Fc6c2eGaxVyOKljnSinKIMVfuYj0qcVkgfJ3n4+1l+tF
csvr0HsHxkDfqood2IV4C01BGyxMIM+aMCs9uL7dInGlAohoOHi5dGSzq9IsGam7
CSdzwkidk4Y2UNmsX7x04ton23qhmuhNHN1mJVG1i4OOM2tkFooc9L3nyw7Xq6n4
lbxc46vDlW1tin5sZzlAnjt3I9GfZdaCZPxHUQEa6D8amvNPF1Za96RZnOCp83LA
i/mSRNbnM5D80DatzENhDMN/Kdbf/euHHxNbOOslPGQUgE7IN21DNjVVPMzOmNq4
igVTRth4SlXRIb8IX4e5ezLj0dG8Y9gAv/MVcfg8VO/ztU4jk0gE400nx6ut1Ix2
DaibQS1DT/ocBxs0NKOIOlp3qs4jU86CxpuEkLlbFk6hhWxpnIjx8EsjJyLvF13q
8HYuswOqqqrhP9lCCQH40q0w40cBTLwBRf7A7gmdG8DZRac2/pjqbiENd9TN/0Y0
SaS4YGj8LKm9m9rkoEMb5JQOuJj5mE+at+p58E/fVx5mP/6zdYP1mphhPes0vEQ9
UEo0szqbIQum0E3xsk7Qwd3u9ajorT+KVEYGNGejC+7nYAkMkpc=
=syZ/
-----END PGP SIGNATURE-----


Reply to: