** Patch added: "patch for focal"
   
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+attachment/5456637/+files/caribou_0.4.21-7_0.4.21-7ubuntu0.1.diff

** Description changed:

  [Impact]
  There is a regression after solving CVE-2020-25712 
(https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25712) in xserver 
(https://gitlab.freedesktop.org/xorg/xserver/-/commit/87c64fc5b0db9f62f4e361444f4b60501ebf67b9)
 that make caribou crash pressing ē.
  
  In cinnamon-screensaver (>=4.2 where integrated the virtual keyboard)
  crash of caribou cause also screensaver crash and make possible access
  without insert the correct password, this introduced a security issue.
  
  [Test Case]
  In cinnamon-screensaver (>=4.2) pressing ē (after long press on e) in virtual 
keyboard (button at the bottom of the screen in the center) make caribou (and 
the screensaver) crash and access without insert the correct password.
  
  [Where problems could occur]
  The following versions of ubuntu are affected by the security caused by 
caribou crash of this issue:
  - Focal (cinnamon 4.4)
  - Groovy (cinnamon 4.6)
  - Hirsute (bug solved with 0.4.21-7.1)
  
- The patch attached in 
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/comments/4 (for 
Focal) have the same changes of 0.4.21-7.1 (debian unstable, debian testing and 
Hirsute) and same patches are used also in some other distros that already 
applied the fix faster (as security issue) and 1 week or more went by without 
experiencing regressions at the moment.
+ The patch attached in #4 (for Focal) have the same changes of 0.4.21-7.1 
(debian unstable, debian testing and Hirsute) and same patches are used also in 
some other distros that already applied the fix faster (as security issue) and 
1 week or more went by without experiencing regressions at the moment.
  The patch is already tested in Focal, can be used also in Groovy (only 
changing focal->groovy).

** Description changed:

  [Impact]
  There is a regression after solving CVE-2020-25712 
(https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25712) in xserver 
(https://gitlab.freedesktop.org/xorg/xserver/-/commit/87c64fc5b0db9f62f4e361444f4b60501ebf67b9)
 that make caribou crash pressing ē.
  
  In cinnamon-screensaver (>=4.2 where integrated the virtual keyboard)
  crash of caribou cause also screensaver crash and make possible access
  without insert the correct password, this introduced a security issue.
  
  [Test Case]
  In cinnamon-screensaver (>=4.2) pressing ē (after long press on e) in virtual 
keyboard (button at the bottom of the screen in the center) make caribou (and 
the screensaver) crash and access without insert the correct password.
  
  [Where problems could occur]
  The following versions of ubuntu are affected by the security caused by 
caribou crash of this issue:
  - Focal (cinnamon 4.4)
  - Groovy (cinnamon 4.6)
  - Hirsute (bug solved with 0.4.21-7.1)
  
- The patch attached in #4 (for Focal) have the same changes of 0.4.21-7.1 
(debian unstable, debian testing and Hirsute) and same patches are used also in 
some other distros that already applied the fix faster (as security issue) and 
1 week or more went by without experiencing regressions at the moment.
+ The patch attached in #10 (for Focal) have the same changes of 0.4.21-7.1 
(debian unstable, debian testing and Hirsute) and same patches are used also in 
some other distros that already applied the fix faster (as security issue) and 
1 week or more went by without experiencing regressions at the moment.
  The patch is already tested in Focal, can be used also in Groovy (only 
changing focal->groovy).

** Description changed:

  [Impact]
  There is a regression after solving CVE-2020-25712 
(https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25712) in xserver 
(https://gitlab.freedesktop.org/xorg/xserver/-/commit/87c64fc5b0db9f62f4e361444f4b60501ebf67b9)
 that make caribou crash pressing ē.
  
  In cinnamon-screensaver (>=4.2 where integrated the virtual keyboard)
  crash of caribou cause also screensaver crash and make possible access
  without insert the correct password, this introduced a security issue.
  
  [Test Case]
  In cinnamon-screensaver (>=4.2) pressing ē (after long press on e) in virtual 
keyboard (button at the bottom of the screen in the center) make caribou (and 
the screensaver) crash and access without insert the correct password.
  
  [Where problems could occur]
  The following versions of ubuntu are affected by the security caused by 
caribou crash of this issue:
  - Focal (cinnamon 4.4)
  - Groovy (cinnamon 4.6)
  - Hirsute (bug solved with 0.4.21-7.1)
  
- The patch attached in #10 (for Focal) have the same changes of 0.4.21-7.1 
(debian unstable, debian testing and Hirsute) and same patches are used also in 
some other distros that already applied the fix faster (as security issue) and 
1 week or more went by without experiencing regressions at the moment.
+ The patch attached in comment #10 (for Focal) have the same changes of 
0.4.21-7.1 (debian unstable, debian testing and Hirsute) and same patches are 
used also in some other distros that already applied the fix faster (as 
security issue) and 1 week or more went by without experiencing regressions at 
the moment.
  The patch is already tested in Focal, can be used also in Groovy (only 
changing focal->groovy).

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to