First published: Wed Oct 14 2009(Updated: )
Chris Coulson reported gnome-screensaver is prone to race condition between two subsequent actions -- shaking the unlock dialog and clearing the screen. A local attacker could use this flaw to cause a denial of service (gnome-screensaver crash), which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended. Upstream bug report: <a href="https://bugzilla.gnome.org/show_bug.cgi?id=598476">https://bugzilla.gnome.org/show_bug.cgi?id=598476</a> Upstream patch: <a href="http://git.gnome.org/browse/gnome-screensaver/commit/?id=ab08cc93f2dc6223c8c00bfa1ca4f2d89069dbe0">http://git.gnome.org/browse/gnome-screensaver/commit/?id=ab08cc93f2dc6223c8c00bfa1ca4f2d89069dbe0</a> CVE Request: <a href="http://www.openwall.com/lists/oss-security/2010/02/12/1">http://www.openwall.com/lists/oss-security/2010/02/12/1</a> References: <a href="http://www.heise.de/newsticker/meldung/Gnome-Bildschirmsperre-in-OpenSuse-Linux-wirkungslos-928580.html">http://www.heise.de/newsticker/meldung/Gnome-Bildschirmsperre-in-OpenSuse-Linux-wirkungslos-928580.html</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gnome Gtk | <2.18.5 | |
GNOME screensaver | <2.28.1 |
http://git.gnome.org/browse/gnome-screensaver/commit/?id=ab08cc93f2dc6223c8c00bfa1ca4f2d89069dbe0
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.