*** This bug is a security vulnerability ***

Public security bug reported:

I had a Windows 10 image running on Virtual Box, and I restarted the
Windows 10 image on virtual box, and left the computer (host and guest)
alone. When I came back, my monitors were turned off (like, in sleep
mode) like they were in sleep mode. When I typed in a few keys to get
everything to wake up again, I was typing into my Windows 10 image my
account password. But then, I moved my mouse over to the other monitor
(the host OS - Ubuntu Linux LTS 16.04), and started doing stuff on my
web browser (Google Chrome), a few seconds after, the screen locked
(almost like if the computer has a brain fart and was like "oh shit,
this was supposed to be locked. Let me fix my mistake.") and I had to
type in the password for the host operating system.

Doesn't this mean that the user had a few unauthorized seconds to do
stuff on the host OS, before being locked out?

Hopefully I explained this well.

ProblemType: Bug
DistroRelease: Ubuntu 16.04
Package: gnome-screensaver 3.6.1-7ubuntu4
ProcVersionSignature: Ubuntu 4.4.0-53.74-generic 4.4.30
Uname: Linux 4.4.0-53-generic x86_64
NonfreeKernelModules: nvidia_uvm nvidia_drm nvidia_modeset nvidia
ApportVersion: 2.20.1-0ubuntu2.4
Architecture: amd64
CurrentDesktop: Unity
Date: Sun Dec 18 22:31:30 2016
GnomeSessionIdleInhibited: No
GnomeSessionInhibitors: None
GsettingsGnomeSession:
 org.gnome.desktop.session session-name 'ubuntu'
 org.gnome.desktop.session idle-delay uint32 300
InstallationDate: Installed on 2016-10-24 (56 days ago)
InstallationMedia: Ubuntu 16.04.1 LTS "Xenial Xerus" - Release amd64 (20160719)
SourcePackage: gnome-screensaver
Symptom: security
Title: Screen locking issue
UpgradeStatus: No upgrade log present (probably fresh install)

** Affects: gnome-screensaver (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: amd64 apport-bug xenial

** Information type changed from Private Security to Public Security

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1651033

Title:
  Virtual Box gives the user a few seconds to do stuff before locking

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/gnome-screensaver/+bug/1651033/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to