The headline is simply wrong.
"So from a superficial analysis anything since 1.10.99.902 could be vulnerable."
That's not _every_ linux screen locker. E.g. ubuntu 10.04 isn't affected.
"So from a superficial analysis anything since 1.10.99.902 could be vulnerable."
That's not _every_ linux screen locker. E.g. ubuntu 10.04 isn't affected.
Meaning that any version of any of Gnome/KDE/XFCE/etc's screen lockers will be defeated by this exploit if they are running in this version of Xorg.
As far as I can tell this is probably true, unless someone knows a locker that uses an alternative method of locking out all keyboard/mouse input?
The bug is in Xorg, if you have any screen-locker running on a version with the bug, then it can be bypassed.
heh, OT rant, ...and i get a email from pg scolding me for using factually correct superlatives in my submissions.
yum update xkeyboard-config
with the Fedora repos enabled fixes the issue now (the fixed in version is xkeyboard-config-2.3-3.fc16.noarch).