PT-2007-1065 · Xscreensaver+1 · Xscreensaver+1

Publicado

2007-05-02

·

Atualizado

2017-10-11

·

CVE-2007-1859

CVSS v2.0

5.4

Média

VetorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: xscreensaver versions prior to 5.02 xscreensaver version 3.33 xscreensaver version 4.10 xscreensaver version 4.18
Description: The issue affects the xscreensaver package and can lead to a breach of confidentiality, integrity, and availability of protected information. Exploitation can be performed both locally and remotely. In certain cases, when using a remote directory service for credentials and there is no network connectivity, xscreensaver may crash and unlock the screen, allowing local users to bypass authentication.
Recommendations: For xscreensaver versions prior to 5.02, update to version 5.02 or later to resolve the issue. For xscreensaver version 3.33, consider disabling the use of remote directory services for credentials until a patch is available. For xscreensaver version 4.10, restrict access to the getpwuid function in drivers/lock.c to minimize the risk of exploitation. For xscreensaver version 4.18, avoid using the package until a fixed version is released.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06963
BDU:2015-07117
BDU:2015-07118
BDU:2015-09572
CVE-2007-1859
RHSA-2007:0322
RHSA-2007_0322

Produtos afetados

Red Hat
Xscreensaver