First published: Thu Jan 21 2010(Updated: )
It was reported [1] that the GNOME screensaver could insecurely unlock a secondary screen when moving from a single screen display to a dual-screen display. If a user were to have a suspended laptop, attach an external monitor, resume, and attempt to unlock the GNOME screensaver, the external display will show the GNOME desktop and can be interacted with, without requiring a password. Upstream has provided a possible patch to correct the issue [2]. <a href="https://access.redhat.com/security/cve/CVE-2010-0285">CVE-2010-0285</a> has been assigned to this issue. [1] <a href="https://bugzilla.gnome.org/show_bug.cgi?id=593616">https://bugzilla.gnome.org/show_bug.cgi?id=593616</a> [2] <a href="http://git.gnome.org/browse/gnome-screensaver/commit/?id=2f597ea9f1f363277fd4dfc109fa41bbc6225aca">http://git.gnome.org/browse/gnome-screensaver/commit/?id=2f597ea9f1f363277fd4dfc109fa41bbc6225aca</a>
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Screensaver |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-557525 is classified as moderate due to potential unauthorized access when unlocking the screensaver on a secondary display.
To fix REDHAT-BUG-557525, users should update their GNOME screensaver to the latest version that addresses this vulnerability.
REDHAT-BUG-557525 affects earlier versions of the GNOME screensaver prior to the security updates that address this issue.
The impact of REDHAT-BUG-557525 allows unauthorized users to potentially access sensitive information on a secondary screen when the primary screen is locked.
Users can mitigate the risks of REDHAT-BUG-557525 by ensuring their screensaver settings require authentication and by applying the latest software updates.