LWN.net Logo

xlockmore: screen lock bypass

Package(s):xlockmore CVE #(s):CVE-2013-4143
Created:July 22, 2013 Updated:July 31, 2013
Description: From the Mageia advisory:

xlockmore before 5.43 contains a security flaw related to potential NULL pointer dereferences when authenticating via glibc 2.17+'s crypt() function. Under certain conditions the NULL pointers can trigger a crash in xlockmore effectively bypassing the screen lock.

Alerts:
Mageia MGASA-2013-0225 2013-07-21
Fedora FEDORA-2013-13258 2013-07-30
Gentoo 201309-03 2013-09-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds