First published: Wed Oct 14 2009(Updated: )
Chris Coulson reported gnome-screensaver is prone to race condition between two subsequent actions -- shaking the unlock dialog and clearing the screen. A local attacker could use this flaw to cause a denial of service (gnome-screensaver crash), which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended. Upstream bug report: <a href="https://bugzilla.gnome.org/show_bug.cgi?id=598476">https://bugzilla.gnome.org/show_bug.cgi?id=598476</a> Upstream patch: <a href="http://git.gnome.org/browse/gnome-screensaver/commit/?id=ab08cc93f2dc6223c8c00bfa1ca4f2d89069dbe0">http://git.gnome.org/browse/gnome-screensaver/commit/?id=ab08cc93f2dc6223c8c00bfa1ca4f2d89069dbe0</a> CVE Request: <a href="http://www.openwall.com/lists/oss-security/2010/02/12/1">http://www.openwall.com/lists/oss-security/2010/02/12/1</a> References: <a href="http://www.heise.de/newsticker/meldung/Gnome-Bildschirmsperre-in-OpenSuse-Linux-wirkungslos-928580.html">http://www.heise.de/newsticker/meldung/Gnome-Bildschirmsperre-in-OpenSuse-Linux-wirkungslos-928580.html</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GTK | <2.18.5 | |
GNOME Screensaver | <2.28.1 |
http://git.gnome.org/browse/gnome-screensaver/commit/?id=ab08cc93f2dc6223c8c00bfa1ca4f2d89069dbe0
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0732 is considered a denial of service vulnerability that can cause gnome-screensaver to crash.
To fix CVE-2010-0732, update gnome-screensaver and GTK to versions above 2.28.1 and 2.18.5 respectively.
CVE-2010-0732 affects users of gnome-screensaver versions prior to 2.28.1 and GTK versions prior to 2.18.5.
Yes, a local attacker can exploit CVE-2010-0732 to crash gnome-screensaver and potentially gain unauthorized access.
The flaw in CVE-2010-0732 is a race condition between the unlock dialog and screen clearing actions.