LWN.net Logo

rPath alert rPSA-2007-0088-1 (xscreensaver)

From:  rPath Update Announcements <announce-noreply@rpath.com>
To:  security-announce@lists.rpath.com, update-announce@lists.rpath.com
Subject:  rPSA-2007-0088-1 xscreensaver
Date:  Thu, 03 May 2007 15:43:05 -0400
Cc:  full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com, lwn@lwn.net

rPath Security Advisory: 2007-0088-1 Published: 2007-05-03 Products: rPath Linux 1 Rating: Major Exposure Level Classification: Local User Deterministic Weakness Updated Versions: xscreensaver=/conary.rpath.com@rpl:devel//1/4.22-1.2-1 References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1859 https://issues.rpath.com/browse/RPL-1293 Description: Previous versions of xscreensaver are vulnerable to an attack that requires that the attacker have physical access. If the system is configured to use remote directory service for login credentials, an attacker who can cause or take advantage of a network failure can cause the xscreensaver process to crash, unlocking the screen, and allowing the attacker unrestricted access to the system as the logged-in user.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds