[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Thunderbird with AppArmor should not be able to render X unusable



Hi,

Please see bug #900840: https://bugs.debian.org/900840

---

thunderbird cannot be started anymore and breaks X. X does not update
the screen anymore, the cursor can still be moved and shows on the
screen while nothing can be clicked on or interacted with. Application
which e.g. play sound seem to still continue running, but cannot be
controlled fia the GUI anymore. The X-server needs to be completely
restarted to fix the issue.

---

it should be added that killing the thunderbird process does not repair the X server...

This was caused by apparmor denying access to the graphics card, the original policy bug has since been fixed.

However, this indicates that it is possible for a client application to render the X server unusable, i.e., a local user DoS attack against the X server? Worst case, you could render a screen, damage the xserver using above issue, then trigger a policy prompt such as polkit and trick the user to click an unwanted option. It's probably minor - as it supposedly requires authenticated access to DRI - but who knows?

Regards,
Erich


Reply to: