USN-4958-1: Caribou vulnerability
17 May 2021
Applications using Caribou could be made to crash if given specially crafted input.
- caribou - Configurable on screen keyboard with scanning mode
It was discovered that the Caribou onscreen keyboard could be made
to crash when given certain input values. An attacker could use this
to bypass screen-locking applications that support using Caribou as
an input mechanism.
The problem can be corrected by updating your system to the following package versions:
After a standard system update you need to restart applications that
use Caribou as an onscreen keyboard to make all the necessary changes.