PT-2009-5428 · X.Org Foundation+1 · X11+3

Published

2009-09-08

·

Updated

2011-12-21

·

CVE-2009-3100

CVSS v2.0

4.0

Medium

VectorAV:L/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: xscreensaver versions in Sun Solaris 9 and 10 xscreensaver versions in OpenSolaris snv 109 through snv 122 xscreensaver version in X11 6.4.1 on Solaris 8
Description: The issue is related to improper handling of Accessibility support, which can cause a system hang when the screen is locked and an attempt is made to launch an Accessibility pop-up window. This is due to a regression in certain Solaris and OpenSolaris patches.
Recommendations: For xscreensaver in Sun Solaris 9 and 10, consider disabling Accessibility support as a temporary workaround until a patch is available. For xscreensaver in OpenSolaris snv 109 through snv 122, restrict access to the screen locking feature to minimize the risk of exploitation. For xscreensaver in X11 6.4.1 on Solaris 8, avoid using the Accessibility pop-up window feature until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-3100

Affected Products

Opensolaris
Solaris
X11
Xscreensaver