KDE Desktop Screensaver Lock Activation Failure Vulnerability
BID:19152
CVE-2006-2933 |Info
KDE Desktop Screensaver Lock Activation Failure Vulnerability
| Bugtraq ID: | 19152 |
| Class: | Design Error |
| CVE: |
CVE-2006-2933 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 25 2006 12:00AM |
| Updated: | Jul 27 2006 04:47PM |
| Credit: | This issue was disclosed in the referenced Red Hat advisory. |
| Vulnerable: |
Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 3 Redhat Desktop 3.0 KDE KDE 3.1.3 KDE KDE 3.1.2 |
| Not Vulnerable: |
Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 |
Discussion
KDE Desktop Screensaver Lock Activation Failure Vulnerability
The KDE desktop is prone to a vulnerability that can cause the manual locking of the desktop to fail or can stop the screensaver from activating.
These issues could have a security impact if the user depends on the locking mechanism to secure their desktop.
The KDE desktop is prone to a vulnerability that can cause the manual locking of the desktop to fail or can stop the screensaver from activating.
These issues could have a security impact if the user depends on the locking mechanism to secure their desktop.
Exploit / POC
KDE Desktop Screensaver Lock Activation Failure Vulnerability
To exploit this issue, attackers need physical access to a vulnerable computer.
To exploit this issue, attackers need physical access to a vulnerable computer.
Solution / Fix
KDE Desktop Screensaver Lock Activation Failure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Reports indicate this issue does not affect KDE versions greater than 3.1.3; Symantec has not confirmed this.
Please see the referenced advisories for more information.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Reports indicate this issue does not affect KDE versions greater than 3.1.3; Symantec has not confirmed this.
Please see the referenced advisories for more information.
References
KDE Desktop Screensaver Lock Activation Failure Vulnerability
References:
References:
- Bugzilla Bug 177755 �?? CVE-2006-2933 occasionally KDE screensaver fails to start (Issue Tracker)
- KDE Home Page (KDE)
- RHSA-2006:0576-7 - kdebase security fix (Red Hat)