First published: Wed Oct 17 2007(Updated: )
Description of problem: xscreensaver has started crashing a few days ago Version-Release number of selected component (if applicable): xscreensaver-5.03-10.fc7.src.rpm How reproducible: sometimes Steps to Reproduce: 1. lock screen 2. leave computer 3. come back and wiggle mouse if screen dark Actual results: screen unlocked without entering password Expected results: screen remains locked until I enter my password Additional info: output of "xscreensaver -sync -verbose -no-capture" will be attached. stupidly enough I forgot to up the ulimit -c from 0. it's running in sync and verbose mode again after "ulimit -c 2048". Will update this BZ if it craps out again.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/0 | <0.4.20070929. | 0.4.20070929. |
XScreenSaver | =5.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5585 is classified with moderate severity due to the potential for system crashes.
To fix CVE-2007-5585, update xscreensaver to the version 0.4.20070929 or later.
CVE-2007-5585 affects xscreensaver version 5.03.
You can reproduce the issue by locking the screen and wiggling the mouse after leaving the computer.
The primary issue with CVE-2007-5585 is that xscreensaver can crash under certain conditions.