First published: Tue Mar 21 2006(Updated: )
gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensaver to crash and access the session via the Ctl+Alt+Keypad-Multiply keyboard sequence, which removes the grab from gnome.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Screensaver | <=2.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1335 is considered a moderate severity vulnerability due to its requirement for physical access to the machine.
To fix CVE-2006-1335, upgrade to GNOME screensaver version 2.14 or higher.
CVE-2006-1335 affects GNOME screensaver versions before 2.14.
CVE-2006-1335 cannot be exploited remotely as it requires physical access to the affected machine.
CVE-2006-1335 allows an attacker with physical access to crash the screensaver and access the session.