Hm, I see the XF86ClearGrab binding is active in my 'xkbcomp :0 -' output on Ubuntu 11.10 (both the mapping and the interpret bits), and I can see XF86ClearGrab show up in xev output, but when I press it when the screensaver is active, nothing happens. Huh?
Posted Jan 19, 2012 18:43 UTC (Thu) by zwenna (subscriber, #64777)
[Link]
Ubuntu 11.10 still has xserver 1.10, so is not vulnerable.
X.org screensaver bypass found
Posted Jan 19, 2012 19:36 UTC (Thu) by __alex (subscriber, #38036)
[Link]
Unless like me you use the xorg-edgers ppa in which case you definitely are vulnerable :(
X.org screensaver bypass found
Posted Jan 19, 2012 22:43 UTC (Thu) by mgedmin (subscriber, #34497)
[Link]
You mean this version of hw/xfree86/dixmods/xkbPrivate.c doesn't handle Private(type=0x86, data="clsgrab"), so there's no harm of that action existing in my xkb config? Now it makes sense to me.