CVE-2007-5585: Medium severity Xscreensaver Xscreensaver vulnerability
Description of problem: xscreensaver has started crashing a few days ago
Version-Release number of selected component (if applicable): xscreensaver-5.03-10.fc7.src.rpm
How reproducible: sometimes
Steps to Reproduce: 1. lock screen 2. leave computer 3. come back and wiggle mouse if screen dark Actual results: screen unlocked without entering password
Expected results: screen remains locked until I enter my password
Additional info: output of "xscreensaver -sync -verbose -no-capture" will be attached. stupidly enough I forgot to up the ulimit -c from 0. it's running in sync and verbose mode again after "ulimit -c 2048". Will update this BZ if it craps out again.
Other sources
xscreensaver 5.03 and earlier, when running without xscreensaver-gl-extras (GL extras) installed, crashes when /usr/bin/xscreensaver-gl-helper does not exist and a user attempts to unlock the screen, which allows attackers with physical access to gain access to the locked session.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5585?
CVE-2007-5585 is classified with moderate severity due to the potential for system crashes.
How do I fix CVE-2007-5585?
To fix CVE-2007-5585, update xscreensaver to the version 0.4.20070929 or later.
What software is affected by CVE-2007-5585?
CVE-2007-5585 affects xscreensaver version 5.03.
How can I reproduce the issue in CVE-2007-5585?
You can reproduce the issue by locking the screen and wiggling the mouse after leaving the computer.
What is the primary issue associated with CVE-2007-5585?
The primary issue with CVE-2007-5585 is that xscreensaver can crash under certain conditions.