pam_panic: Security bug and security fix
This is an announcement about a security bug and a fix release I noticed when I was using xscreensaver:
Reproducing steps
- Having pam_panic in your pam.d of xscreensaver using the password function.
- Trigger the keyboard/mouse to let pam_panic prompt for its password.
- Wait for xscreensaver to pass the timeout.
- xscreensaver crashes and you can use the computer without authentication.
Expected
- …
- …
- …
- xscreensaver should blank out and keep the screen locked.
Fix
Fixed in #47.
What to do
Clone the updated git repo and reinstall pam_panic.