CVE-2004-2655
Summary
| CVE | CVE-2004-2655 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2018-10-03 21:29:00 UTC |
| Description | rdesktop 1.3.1 with xscreensaver 4.14, and possibly other versions, when running on Fedora and possibly other platforms, does not release the keyboard focus when xscreensaver starts, which causes the password to be entered into the active window when the user unlocks the screen. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Xscreensaver | Xscreensaver | 4.14 | All | All | All |
| Application | Xscreensaver | Xscreensaver | 4.16 | All | All | All |
| Application | Xscreensaver | Xscreensaver | 4.17 | All | All | All |
| Application | Xscreensaver | Xscreensaver | 4.14 | All | All | All |
| Application | Xscreensaver | Xscreensaver | 4.16 | All | All | All |
| Application | Xscreensaver | Xscreensaver | 4.17 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisories - Mandriva Linux OS | MANDRIVA | www.mandriva.com | |
| SUSE Update for Multiple Packages - Advisories - Secunia | SECUNIA | secunia.com | |
| ASA-2006-107 (RHSA-2006-0498) | CONFIRM | support.avaya.com | |
| Security Announcement | SUSE | www.novell.com | |
| XScreenSaver rdesktop May Display the Screensaver Password in Another Window - SecurityTracker | SECTRACK | securitytracker.com | |
| Avaya Products XScreenSaver Insecure Temporary File Creation Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| comp.os.linux.security: exposed passwords in Fedora 2 !!!!! | MISC | www.derkeiler.com | |
| Secunia - Advisories - Red Hat update for xscreensaver | SECUNIA | secunia.com | |
| XScreenSaver | CONFIRM | www.jwz.org | |
| SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia | SECUNIA | secunia.com | |
| USN-269-1: xscreensaver vulnerability | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| (Red Hat Issues Fix) XScreenSaver rdesktop May Display the Screensaver Password in Another Window - SecurityTracker | SECTRACK | securitytracker.com | |
| 20060602-01-U | SGI | patches.sgi.com | |
| 188149 – CVE-2004-2655 xscreensaver passes password to other applications | MISC | bugzilla.redhat.com | |
| Support | REDHAT | www.redhat.com | |
| XScreenSaver Local Password Disclosure Vulnerability | BID | www.securityfocus.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.