mate-screensaver and security?

Questions about the project and the distribution - obviously no support questions here please
Post Reply
polarvortex
Level 4
Level 4
Posts: 235
Joined: Sun Mar 23, 2014 1:47 am

mate-screensaver and security?

Post by polarvortex » Mon Jun 17, 2019 8:28 am

I don't know much about the linux world, so I apologize ahead of time if I'm off base with this post or missing something obvious.

It's my understanding that mate-screensaver has a bug that allows you to plug in a monitor to bypass the lock screen to gain access without the user's password? If that's incorrect and it's been patched then this is a dumb post, oops. But if it is correct,

In mate edition it's installed and autorunning by default. And there's nothing about this bug in the known issues in the release notes.
I guess it's upstream, but I think being a security issue maybe it should be mentioned. And there doesn't seem to be a security bulletin section on the website.

I didn't imagine that Mint would include a known security bug for many months that can be used to easily get into a locked computer, and not effectively communicate that, or not patch or disable it.

It's messing with my head, because previously I figured security was amazing in linux mint, and you'd never have to worry that something like this was in it.

gm10
Level 18
Level 18
Posts: 8722
Joined: Thu Jun 21, 2018 5:11 pm

Re: mate-screensaver and security?

Post by gm10 » Mon Jun 17, 2019 8:47 am

Yeah, had been buggy for a long time, then was finally patched in MATE 1.20.2, but that is not currently available in any version of Mint. Mint 19.2 may come with MATE 1.22, I don't know.
Tune up your LM 19.x: ppa:gm10/linuxmint-tools

polarvortex
Level 4
Level 4
Posts: 235
Joined: Sun Mar 23, 2014 1:47 am

Re: mate-screensaver and security?

Post by polarvortex » Tue Jun 18, 2019 6:21 am

I don't think 19.2 should ship with mate-screensaver without the fix.

Are there any other big security bugs in Mint that have been known for months and not patched?

User avatar
Pjotr
Level 21
Level 21
Posts: 13190
Joined: Mon Mar 07, 2011 10:18 am
Location: The Netherlands (Holland)
Contact:

Re: mate-screensaver and security?

Post by Pjotr » Tue Jun 18, 2019 6:26 am

polarvortex wrote:
Tue Jun 18, 2019 6:21 am
I don't think 19.2 should ship with mate-screensaver without the fix.

Are there any other big security bugs in Mint that have been known for months and not patched?
Unpatched security bugs like this one? Doubtlessly. Big ones, i.e. posing a large threat in real life? Not very likely.
Tip: 10 things to do after installing Linux Mint 19.2 Tina
Keep your Linux Mint healthy: Avoid these 10 fatal mistakes
Twitter: twitter.com/easylinuxtips
All in all, horse sense simply makes sense.

gm10
Level 18
Level 18
Posts: 8722
Joined: Thu Jun 21, 2018 5:11 pm

Re: mate-screensaver and security?

Post by gm10 » Tue Jun 18, 2019 6:33 am

polarvortex wrote:
Tue Jun 18, 2019 6:21 am
I don't think 19.2 should ship with mate-screensaver without the fix.
Don't tell me. I'm running MATE 1.23 myself. :P
Tune up your LM 19.x: ppa:gm10/linuxmint-tools

athi
Level 6
Level 6
Posts: 1261
Joined: Sun Mar 30, 2014 10:15 am
Location: USA

Re: mate-screensaver and security?

Post by athi » Tue Jun 18, 2019 7:45 am

Pjotr wrote:
Tue Jun 18, 2019 6:26 am
polarvortex wrote:
Tue Jun 18, 2019 6:21 am
I don't think 19.2 should ship with mate-screensaver without the fix.

Are there any other big security bugs in Mint that have been known for months and not patched?
Unpatched security bugs like this one? Doubtlessly. Big ones, i.e. posing a large threat in real life? Not very likely.
Security bugs comes in 2 primary types, one requires physical access and one that can be use remotely. This screen saver bug requires physical access and if anybody with the right skills set have physical access to the PC, this bug is the least of your problems.
Mint Mate 19.1. Main rig is HP 800G2 I5 6500 16GB ram, 120GB boot drive, 2x3TB, 1x4TB data drives. Oldest rig is Mate 18.3 on Dell D620 with 32bits core duo.

polarvortex
Level 4
Level 4
Posts: 235
Joined: Sun Mar 23, 2014 1:47 am

Re: mate-screensaver and security?

Post by polarvortex » Tue Jun 18, 2019 7:56 am

Pjotr wrote:
Tue Jun 18, 2019 6:26 am
Unpatched security bugs like this one? Doubtlessly. Big ones, i.e. posing a large threat in real life? Not very likely.
People on this forum make a big deal about passwords and not using automatic login and such. I guess they would think that defeating the lock screen is a pretty big deal...

Glad to hear there are no other things like this in Mint that you are immediately aware of.

Post Reply

Return to “Non-technical Questions”