oss-sec mailing list archives

Re: Ubuntu 14.04: security problem in the lock screen


From: Dave Walker <davewalker () ubuntu com>
Date: Sat, 26 Apr 2014 17:09:47 +0100

On 26 Apr 2014 16:07, "Kurt Seifried" <kseifried () redhat com> wrote:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1308572

Probably needs a CVE.

- --
Kurt Seifried Red Hat Security Response Team (SRT)

Hi,

This was discovered (and resolved) in pre-release Ubuntu 14.04. Whilst it
was only this status by 1 day, the exposure risk is to brave early adopters
and developers.

Whilst technically it was present in a Unity release, I cannot think of any
other consumer of Unity than Ubuntu. As the exposed version of Ubuntu
wasn't released, it would seem fair to consider the two together.

I am aware that on occasion CVE's have been issued for development
snapshots, but I haven't seen clear policy on this.

I am not sure if this should be considered widely distributed or not. It
would seem redundant to raise a CVE for inflight development snapshot.
Unless, you believe the exposure to warrant it?

I'm sure someone from Ubuntu Security will chime in, but thought it wise to
respond to avoid an ID being raised in potential error.

Thanks

--
Kind Regards,
Dave Walker

Current thread: