As reported by The H, a vulnerability in Xorg has been discovered that, on affected systems, allows anyone to unlock a locked computer without knowing the user’s password.
The French blogger “Gu1″ has discovered that versions 1.11 and above of X.org’s X Server contain an interesting vulnerability that enables users to gain access to a locked computer. Simultaneously pressing the Ctrl key, the Alt key and the
*key on the numeric keyboard disables a user’s screensaver and unlocks the computer.According to Gu1, the problem is caused by the “AllowClosedownGrabs” debug option: if it is active, pressing the key combination causes any processes that grab mouse or keyboard inputs to shut down – in this case, the screensaver that usually prevents a locked computer from being accessed. Gu1 says that the function had existed up to 2008, but at that time it was disabled by default and well-documented. Apparently, the developers even explicitly pointed out the potential security issues that may exist when used in combination with screensavers. Developers were also able to use an API to disallow the function for their processes. The function was re-introduced last year – “but this time it’s enabled by default, not clearly documented and not even configurable easily”, noted the blogger. X.org developer Peter Hutterer says that this was caused by a miscommunication within the development team: after the function was re-introduced, the developers failed to remove the keyboard combination from the default keymap.
Comment on this article via Google+.
Recently Popular
- Canonical's Board Decimated As 2 More Employees Leave
- Gnome Shell Notifications Explained
- The Solarized Palette
- Gnome 3 Wallpapers
- Citrus: New UI Proposal for Libre Office
- Add Some Useful Tweaks to Gnome 3
- Red Hat is "Obfuscating" the RHEL 6 Kernel Source
- The Future of Linux Mint
- Ubuntu is Shutting Down Off-Topic Mailing List
- Apple Threatens Small, Family-Run Café Over Trademark
Tags
amazon announcement apple canonical cracking design development elopcalypse fedora financial firefox gaming germany gnome gnome3 gnomeshell google government gpl hacked java kernel legal licensing markshuttleworth meego microsoft mozilla nokia novell oracle patents phones playstation politics redhat releases samsung security sony tablets ubuntu unitedstates windows windowsphone
Topics
LXNews covers everything to do with the Linux kernel, Android, free and open source software, the web, digital rights and free culture. We also cover proprietary software, companies and international politics where those intersect with the aforementioned issues. We believe that software freedom is worthless without personal freedom both as a citizen and as a consumer.Open Source News
You can see the news come in via our freelish.us feed before they hit the site and if you think we have missed an important story, please submit it via this form.Comments?
To comment on any of the articles posted on the site, please use the provided links under the content and join our identi.ca conversation.









