Related Vulnerabilities: CVE-2021-33738  

Caribou can be crashed by attempting to insert the character "ē". This issue has security implications for cinnamon-screensaver because a crash of caribou causes the screensaver to crash as well, making access to the session possible without providing the correct password.

Severity Medium

Remote No

Type Authentication bypass

Description

Caribou can be crashed by attempting to insert the character "ē". This issue has security implications for cinnamon-screensaver because a crash of caribou causes the screensaver to crash as well, making access to the session possible without providing the correct password.

AVG-2017 caribou 0.4.21+66+g14f5428-2 0.4.21+66+g14f5428-3 Medium Fixed

https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060
https://gitlab.gnome.org/GNOME/caribou/-/merge_requests/3
https://gitlab.gnome.org/GNOME/caribou/-/commit/d41c8e44b12222a290eaca16703406b113a630c6