CVE-2007-6389: Low severity Gnome screensaver vulnerability
Description of problem:
Quoting Debian bug report: With the addition of the feature to send a message to the logged in user when they return and unlock a locked session, this gives local attackers the ability to read the X selection and clipboard buffers with a middle click on the mouse and a Ctrl+V. I note that the box to leave a message doesn't have a context menu that you could paste via, but it doesn't go far enough.
Additional info:
http://bugzilla.gnome.org/showbug.cgi?id=503005 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=455484
Other sources
The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might allow local users to read the clipboard contents and X selection data for a locked session by using ctrl-V.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6389?
CVE-2007-6389 is considered a moderate severity vulnerability due to its local attack vector.
How does CVE-2007-6389 affect my system?
CVE-2007-6389 allows local attackers to read the X selection and clipboard buffers.
How do I fix CVE-2007-6389?
To fix CVE-2007-6389, it is recommended to update the GNOME screensaver to version 2.20 or later.
Who is affected by CVE-2007-6389?
CVE-2007-6389 affects systems running GNOME screensaver version 2.20.
Is there a workaround for CVE-2007-6389?
A potential workaround for CVE-2007-6389 is to avoid allowing local user access to the affected system.