Bug 118541 - Vulnerability after resume from suspend
Summary: Vulnerability after resume from suspend
Status: RESOLVED DUPLICATE of bug 115123
Alias: None
Product: SUSE LINUX 10.0
Classification: openSUSE
Component: Security (show other bugs)
Version: RC 1
Hardware: x86-64 All
: P5 - None : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-09-23 07:20 UTC by Beau Steward
Modified: 2005-09-23 08:09 UTC (History)
0 users

See Also:
Found By: Other
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Beau Steward 2005-09-23 07:20:32 UTC
In testing suspend to disk and resume, I've discovered that the console is 
locked AFTER resuming rather than BEFORE suspending. If resuming can be slowed, 
such as not allowing a throttled cpu to speed up, the unlock dialog can be 
delayed long enough to disclose information or execute commands. This is only 
locally exploitable. I have been able to reproduce this numerous times to reboot 
my laptop by bringing up a konsole, switching to root, and typing reboot before 
I was prompted to unlock the session.
Comment 1 Marcus Meissner 2005-09-23 08:09:57 UTC
known problem ... due to some design reasons we hopefully can address. 
 
Thanks! 

*** This bug has been marked as a duplicate of 115123 ***