Gnome Screensaver Local Information Disclosure Vulnerability
BID:30096
Info
Gnome Screensaver Local Information Disclosure Vulnerability
| Bugtraq ID: | 30096 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-6389 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 05 2008 12:00AM |
| Updated: | Nov 12 2008 04:14PM |
| Credit: | Josh Smith |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 S.u.S.E. openSUSE 10.3 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 GNOME gnome-screensaver 2.20 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Gnome Screensaver Local Information Disclosure Vulnerability
Gnome Screensaver is prone to a local information-disclosure vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive clipboard contents. Information harvested may aid in further attacks.
Gnome Screensaver 2.20.0 is vulnerable to this issue; other versions may also be affected.
Gnome Screensaver is prone to a local information-disclosure vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive clipboard contents. Information harvested may aid in further attacks.
Gnome Screensaver 2.20.0 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Gnome Screensaver Local Information Disclosure Vulnerability
A specific exploit is not required. An attacker must have local, physical access to the affected computer.
A specific exploit is not required. An attacker must have local, physical access to the affected computer.
Solution / Fix
Gnome Screensaver Local Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 7.10 i386
Ubuntu Ubuntu Linux 6.06 LTS amd64
Ubuntu Ubuntu Linux 7.10 powerpc
Ubuntu Ubuntu Linux 7.10 amd64
Ubuntu Ubuntu Linux 6.06 LTS sparc
Ubuntu Ubuntu Linux 6.06 LTS powerpc
Ubuntu Ubuntu Linux 7.10 sparc
Ubuntu Ubuntu Linux 7.10 lpia
Ubuntu Ubuntu Linux 6.06 LTS i386
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 7.10 i386
-
Ubuntu gnome-screensaver_2.20.0-0ubuntu4.3_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.3_i386.deb
Ubuntu Ubuntu Linux 6.06 LTS amd64
-
Ubuntu gnome-screensaver_2.14.3-0ubuntu1.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.14.3-0ubuntu1.1_amd64.deb
Ubuntu Ubuntu Linux 7.10 powerpc
-
Ubuntu gnome-screensaver_2.20.0-0ubuntu4.3_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.3_powerpc.deb
Ubuntu Ubuntu Linux 7.10 amd64
-
Ubuntu gnome-screensaver_2.20.0-0ubuntu4.3_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.3_amd64.deb
Ubuntu Ubuntu Linux 6.06 LTS sparc
-
Ubuntu gnome-screensaver_2.14.3-0ubuntu1.1_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.14.3-0ubuntu1.1_sparc.deb
Ubuntu Ubuntu Linux 6.06 LTS powerpc
-
Ubuntu gnome-screensaver_2.14.3-0ubuntu1.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.14.3-0ubuntu1.1_powerpc.deb
Ubuntu Ubuntu Linux 7.10 sparc
-
Ubuntu gnome-screensaver_2.20.0-0ubuntu4.3_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.20.0-0ubuntu4.3_sparc.deb
Ubuntu Ubuntu Linux 7.10 lpia
-
Ubuntu gnome-screensaver_2.20.0-0ubuntu4.3_lpia.deb
http://ports.ubuntu.com/pool/main/g/gnome-screensaver/gnome-screensave r_2.20.0-0ubuntu4.3_lpia.deb
Ubuntu Ubuntu Linux 6.06 LTS i386
-
Ubuntu gnome-screensaver_2.14.3-0ubuntu1.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.14.3-0ubuntu1.1_i386.deb
References
Gnome Screensaver Local Information Disclosure Vulnerability
References:
References: