PT-2008-1071 · Gnome+1 · Gnome-Screensaver+1
Published
2008-04-02
·
Updated
2017-09-29
·
CVE-2008-0887
CVSS v2.0
4.7
Medium
| Vector | AV:L/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
gnome-screensaver versions prior to 2.22.1
gnome-screensaver version 2.16.1
gnome-screensaver versions prior to 2.20.0-r3
Description
The issue allows physically proximate attackers to gain access to a locked session when a remote authentication server is enabled and the system experiences a network outage, causing the screensaver to crash upon an unlock attempt. This can lead to a violation of protected information. The exploitation of this issue can be performed locally.
Recommendations
For gnome-screensaver versions prior to 2.22.1, update to version 2.22.1 or later to resolve the issue.
For gnome-screensaver version 2.16.1, update to a version later than 2.16.1 to mitigate the risk.
For gnome-screensaver versions prior to 2.20.0-r3, update to version 2.20.0-r3 or later to fix the issue.
As a temporary workaround, consider disabling remote authentication server functionality until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Gnome-Screensaver