[Desktop-packages] [Bug 1668321] Re: Vulnerability allows read/write/exec access on Ubuntu 16.04 Screenlock as lightdm user

2017-03-12 Thread BIGUENET Quentin
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2017-6590 -- You received this bug notification because you are a member of Desktop Packages, which is subscribed to network-manager-applet in Ubuntu. https://bugs.launchpad.net/bugs/1668321 Title: Vulnerability allows read/write

[Desktop-packages] [Bug 1668321] Re: Vulnerability allows read/write/exec access on Ubuntu 16.04 Screenlock as lightdm user

2017-03-09 Thread Marc Deslauriers
There is no CVE number. Please request one here: https://cveform.mitre.org/ -- You received this bug notification because you are a member of Desktop Packages, which is subscribed to network-manager-applet in Ubuntu. https://bugs.launchpad.net/bugs/1668321 Title: Vulnerability allows read/wri

[Desktop-packages] [Bug 1668321] Re: Vulnerability allows read/write/exec access on Ubuntu 16.04 Screenlock as lightdm user

2017-03-08 Thread BIGUENET Quentin
Is it a cve number delivered for this vuln ? -- You received this bug notification because you are a member of Desktop Packages, which is subscribed to network-manager-applet in Ubuntu. https://bugs.launchpad.net/bugs/1668321 Title: Vulnerability allows read/write/exec access on Ubuntu 16.04 S

[Desktop-packages] [Bug 1668321] Re: Vulnerability allows read/write/exec access on Ubuntu 16.04 Screenlock as lightdm user

2017-03-08 Thread Launchpad Bug Tracker
This bug was fixed in the package network-manager-applet - 1.4.2-1ubuntu3 --- network-manager-applet (1.4.2-1ubuntu3) zesty; urgency=medium * SECURITY UPDATE: file access from login screen (LP: #1668321) - debian/patches/applet-Check-the-user-has-permission-to-modify-befor.patch

[Desktop-packages] [Bug 1668321] Re: Vulnerability allows read/write/exec access on Ubuntu 16.04 Screenlock as lightdm user

2017-03-08 Thread Marc Deslauriers
Thanks, I've updated the online version of the USN to properly credit you: https://www.ubuntu.com/usn/usn-3217-1/ -- You received this bug notification because you are a member of Desktop Packages, which is subscribed to network-manager-applet in Ubuntu. https://bugs.launchpad.net/bugs/1668321

[Desktop-packages] [Bug 1668321] Re: Vulnerability allows read/write/exec access on Ubuntu 16.04 Screenlock as lightdm user

2017-03-08 Thread BIGUENET Quentin
> Marc Deslauriers (mdeslaur) wrote on 2017-03-06: #34 > We will probably be publishing updates for this issue on 2017-03-07. > Who do we credit for discovery of this vulnerability? (Our policy is to credit individuals, not > > organizations...names please...) We discovered Frederic Bardy (f

[Desktop-packages] [Bug 1668321] Re: Vulnerability allows read/write/exec access on Ubuntu 16.04 Screenlock as lightdm user

2017-03-07 Thread xtsbdu3reyrbrmroezob
Nice find. There is another lock screen bypass that still exists if you hold right click option down before the screensaver activates. I don't believe that has even been fully and properly patched and has existed for years. And now the accessibility features seem like ripe targets for further revie

[Desktop-packages] [Bug 1668321] Re: Vulnerability allows read/write/exec access on Ubuntu 16.04 Screenlock as lightdm user

2017-03-07 Thread Ubuntu Foundations Team Bug Bot
** Tags added: patch -- You received this bug notification because you are a member of Desktop Packages, which is subscribed to network-manager-applet in Ubuntu. https://bugs.launchpad.net/bugs/1668321 Title: Vulnerability allows read/write/exec access on Ubuntu 16.04 Screenlock as lightdm u

[Desktop-packages] [Bug 1668321] Re: Vulnerability allows read/write/exec access on Ubuntu 16.04 Screenlock as lightdm user

2017-03-07 Thread Launchpad Bug Tracker
This bug was fixed in the package network-manager-applet - 1.2.6-0ubuntu1.1 --- network-manager-applet (1.2.6-0ubuntu1.1) yakkety-security; urgency=medium * SECURITY UPDATE: file access from login screen (LP: #1668321) - debian/patches/applet-Check-the-user-has-permission-to-mod

[Desktop-packages] [Bug 1668321] Re: Vulnerability allows read/write/exec access on Ubuntu 16.04 Screenlock as lightdm user

2017-03-07 Thread Launchpad Bug Tracker
This bug was fixed in the package network-manager-applet - 0.9.4.1-0ubuntu2.6 --- network-manager-applet (0.9.4.1-0ubuntu2.6) precise-security; urgency=medium * SECURITY UPDATE: file access from login screen (LP: #1668321) - debian/patches/applet-Check-the-user-has-permission-to

[Desktop-packages] [Bug 1668321] Re: Vulnerability allows read/write/exec access on Ubuntu 16.04 Screenlock as lightdm user

2017-03-07 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Desktop Packages, which is subscribed to network-manager-applet in Ubuntu. https://bugs.launchpad.net/bugs/1668321 Title: Vulnerability allows read/write/exec