PT-2019-6481 · Opensc+1 · Libpam-Opensc+1

Peter Palfrader

+1

·

Published

2019-11-06

·

Updated

2019-11-08

·

CVE-2006-0061

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions xlockmore versions 5.13 through 5.22
Description The issue allows unauthorized users to access the X session due to a segfault when using libpam-opensc, which returns the underlying xsession.
Recommendations For xlockmore versions 5.13 through 5.22, consider disabling the use of libpam-opensc as a temporary workaround until a patch is available. Restrict access to the X session to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-0061

Affected Products

Libpam-Opensc
Xlockmore