PT-2007-1065 · Xscreensaver+1 · Xscreensaver+1

Published

2007-05-02

·

Updated

2017-10-11

·

CVE-2007-1859

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: xscreensaver versions prior to 5.02 xscreensaver version 3.33 xscreensaver version 4.10 xscreensaver version 4.18
Description: The issue affects the xscreensaver package and can lead to a breach of confidentiality, integrity, and availability of protected information. Exploitation can be performed both locally and remotely. In certain cases, when using a remote directory service for credentials and there is no network connectivity, xscreensaver may crash and unlock the screen, allowing local users to bypass authentication.
Recommendations: For xscreensaver versions prior to 5.02, update to version 5.02 or later to resolve the issue. For xscreensaver version 3.33, consider disabling the use of remote directory services for credentials until a patch is available. For xscreensaver version 4.10, restrict access to the getpwuid function in drivers/lock.c to minimize the risk of exploitation. For xscreensaver version 4.18, avoid using the package until a fixed version is released.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06963
BDU:2015-07117
BDU:2015-07118
BDU:2015-09572
CVE-2007-1859
RHSA-2007:0322
RHSA-2007_0322

Affected Products

Red Hat
Xscreensaver