GNOME ScreenSaver Lock Bypass Vulnerability
BID:54810
Info
GNOME ScreenSaver Lock Bypass Vulnerability
| Bugtraq ID: | 54810 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2012-3452 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 06 2012 12:00AM |
| Updated: | Aug 06 2012 12:00AM |
| Credit: | Kurt Seifried |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
GNOME ScreenSaver Lock Bypass Vulnerability
The 'gnome-screensaver' screensaver is prone to a vulnerability that allows an attacker who has physical console access to bypass the user's locked screen.
An attacker with physical access to the desktop may be able to bypass the desktop-locking screensaver on dual-monitor. This may grant the attacker access to another desktop screens which is permanently unlocked and usable.
GNOME gnome-screensaver 3.4.2 is vulnerable.
The 'gnome-screensaver' screensaver is prone to a vulnerability that allows an attacker who has physical console access to bypass the user's locked screen.
An attacker with physical access to the desktop may be able to bypass the desktop-locking screensaver on dual-monitor. This may grant the attacker access to another desktop screens which is permanently unlocked and usable.
GNOME gnome-screensaver 3.4.2 is vulnerable.
Exploit / POC
GNOME ScreenSaver Lock Bypass Vulnerability
To exploit this issue, attackers require physical console access.
To exploit this issue, attackers require physical console access.
Solution / Fix
GNOME ScreenSaver Lock Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.