CVE-2006-0061: Critical severity Sillycycle Xlockmore vulnerability
Published Jul 13, 2005
·Updated
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.
Affected Software
6 affected components
debian/xlockmore
debian/1:5.13-2.1<=undefined
debian/5.22-1.1<=undefined
debian/xlockmore<=5.13-2.1
Sillycycle Xlockmore=5.13
Sillycycle Xlockmore=5.22
Remediation
Patch Available
Event History
Nov 6, 2019
CVE Published
02:15 AM
CVE Published
via MITRE·06:57 AM
Data Sourced
via MITRE·06:57 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0061?
CVE-2006-0061 is considered a high severity vulnerability as it allows unauthorized access to the X session.
2
How do I fix CVE-2006-0061?
To mitigate CVE-2006-0061, you should upgrade xlockmore to a version higher than 5.22.
3
What software is affected by CVE-2006-0061?
CVE-2006-0061 affects xlockmore versions 5.13 and 5.22.
4
What impact does CVE-2006-0061 have on system security?
CVE-2006-0061 allows unauthorized users to gain access to active X sessions, compromising system security.
5
Is there a workaround for CVE-2006-0061?
As a temporary workaround for CVE-2006-0061, it is advisable to avoid using libpam-opensc with xlockmore.