PT-2004-3545 · Rdesktop+1 · Rdesktop+1
Publicado
2004-12-31
·
Atualizado
2018-10-03
·
CVE-2004-2655
CVSS v2.0
5.4
Média
| Vetor | AV:N/AC:H/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
rdesktop version 1.3.1
Description
The issue occurs when rdesktop is used in conjunction with xscreensaver, specifically version 4.14, on Fedora and possibly other platforms. When xscreensaver starts, rdesktop fails to release the keyboard focus, resulting in the password being entered into the active window when the user unlocks the screen.
Recommendations
For rdesktop version 1.3.1, consider disabling the use of xscreensaver as a temporary workaround until a patch is available. Restrict access to sensitive information when the screen is locked to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Rdesktop
Xscreensaver