xlockmore 'dclock' Mode Security Bypass Vulnerability
BID:56169
CVE-2012-4524 |Info
xlockmore 'dclock' Mode Security Bypass Vulnerability
| Bugtraq ID: | 56169 |
| Class: | Design Error |
| CVE: |
CVE-2012-4524 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 22 2012 12:00AM |
| Updated: | May 07 2015 05:11PM |
| Credit: | Ignatios Souvatzis |
| Vulnerable: |
Tux xlockmore 5.40 Tux xlockmore 5.39 Tux xlockmore 5.38 Tux xlockmore 5.0 Gentoo Linux |
| Not Vulnerable: | |
Discussion
xlockmore 'dclock' Mode Security Bypass Vulnerability
xlockmore is prone to a security-bypass vulnerability.
An attacker with local physical access can exploit this issue to gain unauthorized access to the system, which may lead to further attacks.
xlockmore 5.0 through 5.40 are vulnerable; other versions may also be affected.
xlockmore is prone to a security-bypass vulnerability.
An attacker with local physical access can exploit this issue to gain unauthorized access to the system, which may lead to further attacks.
xlockmore 5.0 through 5.40 are vulnerable; other versions may also be affected.
Exploit / POC
xlockmore 'dclock' Mode Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
xlockmore 'dclock' Mode Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
xlockmore 'dclock' Mode Security Bypass Vulnerability
References:
References:
- (CVE-2012-4524) CVE-2012-4524 xlockmore: Screensaver crash (screen lock bypass) (Jan Lieskovsky)
- CVE id request: xlockmore vulnerability: local access (Ignatios Souvatzis)
- xlockmore Homepage (Tux)