gnome-screensaver Timeout Security Bypass Vulnerability
BID:37240
Info
gnome-screensaver Timeout Security Bypass Vulnerability
| Bugtraq ID: | 37240 |
| Class: | Design Error |
| CVE: |
CVE-2009-4641 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 07 2009 12:00AM |
| Updated: | Feb 17 2010 10:43PM |
| Credit: | Karmic |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 amd64 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 GNOME gnome-screensaver 2.28 GNOME gnome-screensaver 0 |
| Not Vulnerable: | |
Discussion
gnome-screensaver Timeout Security Bypass Vulnerability
The 'gnome-screensaver' program is prone to a security-bypass vulnerability.
An attacker with physical access to the affected computer can exploit this issue to gain unauthorized access to an unlocked session. Successful exploits may lead to other attacks.
The 'gnome-screensaver' program is prone to a security-bypass vulnerability.
An attacker with physical access to the affected computer can exploit this issue to gain unauthorized access to an unlocked session. Successful exploits may lead to other attacks.
Exploit / POC
gnome-screensaver Timeout Security Bypass Vulnerability
An attacker would only need physical access to an affected computer.
An attacker would only need physical access to an affected computer.
Solution / Fix
gnome-screensaver Timeout Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Ubuntu Ubuntu Linux 9.10 sparc
Mandriva Linux Mandrake 2010.0 x86_64
Ubuntu Ubuntu Linux 9.10 lpia
Ubuntu Ubuntu Linux 9.10 i386
Mandriva Linux Mandrake 2010.0
Ubuntu Ubuntu Linux 9.10 powerpc
Ubuntu Ubuntu Linux 9.10 amd64
Solution:
Updates are available. Please see the references for details.
Ubuntu Ubuntu Linux 9.10 sparc
-
Ubuntu gnome-screensaver_2.28.0-0ubuntu3.1_sparc.deb
http://ports.ubuntu.com/pool/main/g/gnome-screensaver/gnome-screensave r_2.28.0-0ubuntu3.1_sparc.deb
Mandriva Linux Mandrake 2010.0 x86_64
-
Mandriva gnome-screensaver-2.28.3-1.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 9.10 lpia
-
Ubuntu gnome-screensaver_2.28.0-0ubuntu3.1_lpia.deb
http://ports.ubuntu.com/pool/main/g/gnome-screensaver/gnome-screensave r_2.28.0-0ubuntu3.1_lpia.deb
Ubuntu Ubuntu Linux 9.10 i386
-
Ubuntu gnome-screensaver_2.28.0-0ubuntu3.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.28.0-0ubuntu3.1_i386.deb
Mandriva Linux Mandrake 2010.0
-
Mandriva gnome-screensaver-2.28.3-1.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 9.10 powerpc
-
Ubuntu gnome-screensaver_2.28.0-0ubuntu3.1_powerpc.deb
http://ports.ubuntu.com/pool/main/g/gnome-screensaver/gnome-screensave r_2.28.0-0ubuntu3.1_powerpc.deb
Ubuntu Ubuntu Linux 9.10 amd64
-
Ubuntu gnome-screensaver_2.28.0-0ubuntu3.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome- screensaver_2.28.0-0ubuntu3.1_amd64.deb
References
gnome-screensaver Timeout Security Bypass Vulnerability
References:
References:
- Bug 600488 - Totem is leaking session inhibitors (Chris Coulson)
- gnome-screensaver Homepage (GNOME)