Skip to content

Introduce security patch 2021.3.5 to 2022.1beta3#13534

Merged
feerrenrut merged 2 commits into
betafrom
prepare2022.1beta3
Mar 25, 2022
Merged

Introduce security patch 2021.3.5 to 2022.1beta3#13534
feerrenrut merged 2 commits into
betafrom
prepare2022.1beta3

Conversation

@seanbudd

Copy link
Copy Markdown
Member

Introduce security fix from the 2021.3.5 patch release.
This can be a squash commit as rc and beta have diverged, and the security patch couldn't share a merge-base with beta.

Unauthenticated users can modify NVDAs system profile for symbol pronunciation. This affects all users first (sign-on) interaction with the system. This action is intended to be limited to signed in users with administrator privileges.
If unexpected symbols are being replaced, a user may experience a denial of service. For example, being unable to sign-in to Windows.

The symbol pronunciation dialog is disabled in secure mode

1. Assign a gesture to "Shows the NVDA symbol pronunciation dialog".
2. Copy the config to secure screens via General Preferences
3. Run NVDA in secure mode with `-s`
4. Use the input gesture, note that the dialog is not opened
@seanbudd seanbudd requested a review from feerrenrut March 25, 2022 00:42
@seanbudd seanbudd requested a review from a team as a code owner March 25, 2022 00:42
@feerrenrut feerrenrut merged commit d609af2 into beta Mar 25, 2022
@feerrenrut feerrenrut deleted the prepare2022.1beta3 branch March 25, 2022 01:20
@nvaccessAuto nvaccessAuto added this to the 2022.2 milestone Mar 25, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants