A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulnerability is to system availability.
{
"binaries": [
{
"binary_name": "caribou",
"binary_version": "0.4.20-1"
},
{
"binary_name": "caribou-antler",
"binary_version": "0.4.20-1"
},
{
"binary_name": "gir1.2-caribou-1.0",
"binary_version": "0.4.20-1"
},
{
"binary_name": "libcaribou-common",
"binary_version": "0.4.20-1"
},
{
"binary_name": "libcaribou-gtk-module",
"binary_version": "0.4.20-1"
},
{
"binary_name": "libcaribou-gtk3-module",
"binary_version": "0.4.20-1"
},
{
"binary_name": "libcaribou0",
"binary_version": "0.4.20-1"
}
]
}
{
"binaries": [
{
"binary_name": "caribou",
"binary_version": "0.4.21-5"
},
{
"binary_name": "caribou-antler",
"binary_version": "0.4.21-5"
},
{
"binary_name": "gir1.2-caribou-1.0",
"binary_version": "0.4.21-5"
},
{
"binary_name": "libcaribou-common",
"binary_version": "0.4.21-5"
},
{
"binary_name": "libcaribou-gtk-module",
"binary_version": "0.4.21-5"
},
{
"binary_name": "libcaribou-gtk3-module",
"binary_version": "0.4.21-5"
},
{
"binary_name": "libcaribou0",
"binary_version": "0.4.21-5"
}
]
}