PT-2010-2646 · Kde · Xscreensaver+2

Felix Lemke

·

Publicado

2010-03-03

·

Atualizado

2010-03-04

·

CVE-2010-0923

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions KDE SC version 4.4.0
Description A race condition exists in the KRunner lock module, specifically in the workspace/krunner/lock/lockdlg.cc file, allowing physically proximate attackers to bypass KScreenSaver screen locking. This can be achieved by pressing the Enter key at a certain time, related to the handling of multiple forked processes.
Recommendations For KDE SC version 4.4.0, consider disabling the KScreenSaver screen locking feature until a patch is available to prevent exploitation of this issue. Restrict access to workstations to minimize the risk of unauthorized access.

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-0923

Produtos afetados

Kde Sc
Krunner
Xscreensaver