First published: Wed Mar 03 2010(Updated: )
Race condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock module in kdebase in KDE SC 4.4.0 allows physically proximate attackers to bypass KScreenSaver screen locking and access an unattended workstation by pressing the Enter key at a certain time, related to multiple forked processes.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE SC | =4.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0923 is classified as a medium severity vulnerability that allows unauthorized access to an unattended workstation.
CVE-2010-0923 allows an attacker to bypass KScreenSaver by exploiting a race condition in the KRunner lock module.
CVE-2010-0923 specifically affects KDE SC version 4.4.0.
The potential consequences of CVE-2010-0923 include unauthorized access to sensitive information on an unattended workstation.
To mitigate CVE-2010-0923, it is recommended to update to a patched version of KDE SC that addresses the vulnerability.