xlockmore: screen lock bypass
| Package(s): | xlockmore | CVE #(s): | CVE-2013-4143 | ||||||||||||
| Created: | July 22, 2013 | Updated: | July 31, 2013 | ||||||||||||
| Description: | From the Mageia advisory:
xlockmore before 5.43 contains a security flaw related to potential NULL pointer dereferences when authenticating via glibc 2.17+'s crypt() function. Under certain conditions the NULL pointers can trigger a crash in xlockmore effectively bypassing the screen lock. | ||||||||||||||
| Alerts: |
| ||||||||||||||
