PT-2010-2646 · Kde · Xscreensaver+2
Felix Lemke
·
Published
2010-03-03
·
Updated
2010-03-04
·
CVE-2010-0923
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
KDE SC version 4.4.0
Description
A race condition exists in the KRunner lock module, specifically in the workspace/krunner/lock/lockdlg.cc file, allowing physically proximate attackers to bypass KScreenSaver screen locking. This can be achieved by pressing the Enter key at a certain time, related to the handling of multiple forked processes.
Recommendations
For KDE SC version 4.4.0, consider disabling the KScreenSaver screen locking feature until a patch is available to prevent exploitation of this issue. Restrict access to workstations to minimize the risk of unauthorized access.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kde Sc
Krunner
Xscreensaver