First published: Wed May 02 2007(Updated: )
XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Enterprise Linux | =2.1 | |
Redhat Enterprise Linux | =2.1 | |
Redhat Enterprise Linux | =2.1 | |
Redhat Enterprise Linux | =3.0 | |
Redhat Enterprise Linux | =3.0 | |
Redhat Enterprise Linux | =3.0 | |
Redhat Enterprise Linux | =4.0 | |
Redhat Enterprise Linux | =4.0 | |
Redhat Enterprise Linux | =4.0 | |
Redhat Enterprise Linux Desktop | =3.0 | |
Redhat Enterprise Linux Desktop | =4.0 | |
Redhat Linux Advanced Workstation | =2.1 | |
Xscreensaver Xscreensaver | =4.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.