Gnome-Screensaver With Compiz Lock Bypass Vulnerability
BID:26188
Info
Gnome-Screensaver With Compiz Lock Bypass Vulnerability
| Bugtraq ID: | 26188 |
| Class: | Unknown |
| CVE: |
CVE-2007-3920 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 23 2007 12:00AM |
| Updated: | Apr 13 2015 10:07PM |
| Credit: | Jens Askengren is credited with discovering this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE Suse Linux Enterprise Desktop 10 SP2 SuSE Suse Linux Enterprise Desktop 10 SP1 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 Redhat Fedora 7 Redhat Enterprise Linux Optional Productivity Application 5 server Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client GNOME gnome-screensaver 2.20 Compiz Compiz 0.5.2 |
| Not Vulnerable: | |
Discussion
Gnome-Screensaver With Compiz Lock Bypass Vulnerability
Gnome-screensaver is prone to a vulnerability that allows an attacker who has physical console access to bypass the user's locked screen.
This issue affects gnome-screensaver released with Ubuntu 7.10; other versions may also be affected. Fixes from Ubuntu are available.
Gnome-screensaver is prone to a vulnerability that allows an attacker who has physical console access to bypass the user's locked screen.
This issue affects gnome-screensaver released with Ubuntu 7.10; other versions may also be affected. Fixes from Ubuntu are available.
Exploit / POC
Gnome-Screensaver With Compiz Lock Bypass Vulnerability
To exploit this issue, attackers require physical console access.
To exploit this issue, attackers require physical console access.
Solution / Fix
Gnome-Screensaver With Compiz Lock Bypass Vulnerability
Solution:
Please see the referenced advisories for details.
Ubuntu Ubuntu Linux 7.10 i386
Ubuntu Ubuntu Linux 7.10 powerpc
Ubuntu Ubuntu Linux 7.10 amd64
Ubuntu Ubuntu Linux 7.10 sparc
Solution:
Please see the referenced advisories for details.
Ubuntu Ubuntu Linux 7.10 i386
-
Ubuntu gnome-screensaver vulnerability
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.2_sparc.deb -
Ubuntu gnome-screensaver vulnerability
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.2_powerpc.deb -
Ubuntu gnome-screensaver vulnerability
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.2_i386.deb
Ubuntu Ubuntu Linux 7.10 powerpc
-
Ubuntu gnome-screensaver vulnerability
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.2_sparc.deb -
Ubuntu gnome-screensaver vulnerability
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.2_powerpc.deb
Ubuntu Ubuntu Linux 7.10 amd64
-
Ubuntu gnome-screensaver vulnerability
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.2_sparc.deb -
Ubuntu gnome-screensaver vulnerability
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.2_powerpc.deb -
Ubuntu gnome-screensaver vulnerability
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.2_i386.deb -
Ubuntu gnome-screensaver vulnerability
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.2_amd64.deb
Ubuntu Ubuntu Linux 7.10 sparc
-
Ubuntu gnome-screensaver vulnerability
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.2_sparc.deb
References
Gnome-Screensaver With Compiz Lock Bypass Vulnerability
References:
References:
- Compiz Homepage (Compiz)
- GNOME Homepage (GNOME)
- [USN-537-1] gnome-screensaver vulnerability (Kees Cook
) - RHSA-2008:0485-4 - Low: compiz security update (Red Hat)