*** This bug is a security vulnerability ***
You have been subscribed to a public security bug by Mike Salvatore
(mikesalvatore):
Plain text Linux user id password exposed in calculator input box.
The first character of the password is dropped.
This is reproducible as follows:
1. allow screen saver to kick in or invoke it manually with ctrl+alt+l
2. type in password
3. hit enter
4. view password in input box of calculator (less first character)
Note the calculator window has the desktop focus and the input box is
empty.
ProblemType: Bug
DistroRelease: Ubuntu 16.04
Package: gnome-calculator 1:3.18.3-0ubuntu1.16.04.1
ProcVersionSignature: Ubuntu 4.15.0-39.42~16.04.1-generic 4.15.18
Uname: Linux 4.15.0-39-generic x86_64
ApportVersion: 2.20.1-0ubuntu2.18
Architecture: amd64
CurrentDesktop: GNOME
Date: Wed Nov 28 16:37:44 2018
ExecutablePath: /usr/bin/gnome-calculator
InstallationDate: Installed on 2018-11-14 (13 days ago)
InstallationMedia: Ubuntu 16.04.5 LTS "Xenial Xerus" - Release amd64 (20180731)
ProcEnviron:
PATH=(custom, user)
XDG_RUNTIME_DIR=<set>
LANG=en_US.UTF-8
SHELL=/bin/bash
SourcePackage: gnome-calculator
UpgradeStatus: No upgrade log present (probably fresh install)
** Affects: gnome-screensaver (Ubuntu)
Importance: Undecided
Status: New
** Tags: amd64 apport-bug xenial
--
password exposed in calculator input box
https://bugs.launchpad.net/bugs/1805715
You received this bug notification because you are a member of Ubuntu Bugs,
which is subscribed to the bug report.
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs