Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The headline is simply wrong.

"So from a superficial analysis anything since 1.10.99.902 could be vulnerable."

That's not _every_ linux screen locker. E.g. ubuntu 10.04 isn't affected.



I took the 'every' portion to mean that every screen locker is affected on the vulnerable versions of Xorg server, not that every version of Xorg is affected.

Meaning that any version of any of Gnome/KDE/XFCE/etc's screen lockers will be defeated by this exploit if they are running in this version of Xorg.

As far as I can tell this is probably true, unless someone knows a locker that uses an alternative method of locking out all keyboard/mouse input?


presumably because 10.04 is using an older version, being almost 2 years old now.


Even the latest Ubuntu (11.10) isn't affected, having xorg version 1.10.4.


I think that was his point. "Every windows machine affected" doesn't mean Windows 7 only.


I think it's pretty clear: "Every Linux screen locker" means every screen locking program that runs on linux, not every version of linux.

The bug is in Xorg, if you have any screen-locker running on a version with the bug, then it can be bypassed.


Ubuntu 11.04 is not affected either


Even ubuntu 12.04 alpha 1 still uses 1.10.4, so it seems NO ubuntu versions were affected


most new distros are. debian-sid uses 1.11

heh, OT rant, ...and i get a email from pg scolding me for using factually correct superlatives in my submissions.


It would be interesting to see which distros are and are not affected. If Fedora 16 is unaffected, I'm going to disagree with your assertion that "most new distros are". Debian stable is unaffected, for example, so the production Debian builds aren't vulnerable.


For fedora 16 there is a fix available here https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0064


  yum update xkeyboard-config
with the Fedora repos enabled fixes the issue now (the fixed in version is xkeyboard-config-2.3-3.fc16.noarch).


Confirmed with Debian Wheezy (testing). Dell Latitude E6520 has a numpad so screen lock was defeated with simply "Ctrl+Alt+*". :-(


Confirmed on Debian Testing


Confirming that Fedora 16 is affected, with the latest updates as of the time of this writing.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: