*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Seth Arnold (seth-arnold):


I have a virtualbox running a Windows 7 64 bit on my Ubuntu 12.04 64 bit. If 
the Windows window is on focus and i am inactive, then my screen is locked 
after a certain amount of time and should normally ask for my password. But it 
only does so if a change the focus to a window other than my virtual machine.

Worse than that, if I hurry after my screen should be locked, I perform
some actions on my Ubuntu host before the password prompt locks the
screen. So the presence of my virtualbox allows people to open a
terminal on the host and type any command in the worst case. This is a
security issue.

Ubuntu: 12.04 64 bit
Window Manager: gnome-shell
VM: Oracle VM VirtualBox Manager 4.1.12_Ubuntu
Screen saver: gnome-screensaver 3.4.1

ProblemType: Bug
DistroRelease: Ubuntu 12.04
Package: gnome-screensaver 3.4.1-0ubuntu1
ProcVersionSignature: Ubuntu 3.2.0-37.58-generic 3.2.35
Uname: Linux 3.2.0-37-generic x86_64
NonfreeKernelModules: nvidia
ApportVersion: 2.0.1-0ubuntu17.1
Architecture: amd64
Date: Wed Feb 13 17:19:45 2013
GnomeSessionIdleInhibited: No
GnomeSessionInhibitors: None
GsettingsGnomeSession:
 org.gnome.desktop.session idle-delay uint32 600
 org.gnome.desktop.session session-name 'ubuntu'
InstallationMedia: Ubuntu 12.04 LTS "Precise Pangolin" - Release amd64 
(20120423)
MarkForUpload: True
ProcEnviron:
 TERM=xterm
 PATH=(custom, no user)
 LANG=de_DE.UTF-8
 SHELL=/bin/bash
SourcePackage: gnome-screensaver
UpgradeStatus: No upgrade log present (probably fresh install)
WindowManager: No value set for 
`/desktop/gnome/session/required_components/windowmanager'

** Affects: gnome-screensaver (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: amd64 apport-bug precise
-- 
screen lock by timeout does not affect vm
https://bugs.launchpad.net/bugs/1124282
You received this bug notification because you are a member of Ubuntu Bugs, 
which is subscribed to the bug report.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to