First published: Tue Nov 10 2015(Updated: )
driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu Linux | =12.04 | |
XScreenSaver | =5.33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8025 is classified as a high severity vulnerability due to the potential for an unauthorized user to bypass the lock screen.
To fix CVE-2015-8025, upgrade XScreenSaver to version 5.34 or later, or apply available patches for affected distributions.
CVE-2015-8025 affects users of XScreenSaver versions prior to 5.34 and Ubuntu Linux 12.04 utilizing XScreenSaver.
CVE-2015-8025 can be exploited by physically proximate attackers who can manipulate monitor connections.
XScreenSaver is the software component where the vulnerability exists, allowing attackers to bypass the lock screen under certain conditions.