PT-2004-3545 · Rdesktop+1 · Rdesktop+1

Published

2004-12-31

·

Updated

2018-10-03

·

CVE-2004-2655

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions rdesktop version 1.3.1
Description The issue occurs when rdesktop is used in conjunction with xscreensaver, specifically version 4.14, on Fedora and possibly other platforms. When xscreensaver starts, rdesktop fails to release the keyboard focus, resulting in the password being entered into the active window when the user unlocks the screen.
Recommendations For rdesktop version 1.3.1, consider disabling the use of xscreensaver as a temporary workaround until a patch is available. Restrict access to sensitive information when the screen is locked to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2655
RHSA-2006:0498

Affected Products

Rdesktop
Xscreensaver