REDHAT-BUG-557525: Medium severity gnome screensaver vulnerability
It was reported [1] that the GNOME screensaver could insecurely unlock a secondary screen when moving from a single screen display to a dual-screen display. If a user were to have a suspended laptop, attach an external monitor, resume, and attempt to unlock the GNOME screensaver, the external display will show the GNOME desktop and can be interacted with, without requiring a password.
Upstream has provided a possible patch to correct the issue [2].
CVE-2010-0285 has been assigned to this issue.
[1] https://bugzilla.gnome.org/showbug.cgi?id=593616 [2] http://git.gnome.org/browse/gnome-screensaver/commit/?id=2f597ea9f1f363277fd4dfc109fa41bbc6225aca
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-557525?
The severity of REDHAT-BUG-557525 is classified as moderate due to potential unauthorized access when unlocking the screensaver on a secondary display.
How do I fix REDHAT-BUG-557525?
To fix REDHAT-BUG-557525, users should update their GNOME screensaver to the latest version that addresses this vulnerability.
What versions of GNOME screensaver are affected by REDHAT-BUG-557525?
REDHAT-BUG-557525 affects earlier versions of the GNOME screensaver prior to the security updates that address this issue.
What is the impact of REDHAT-BUG-557525?
The impact of REDHAT-BUG-557525 allows unauthorized users to potentially access sensitive information on a secondary screen when the primary screen is locked.
How can users mitigate the risks associated with REDHAT-BUG-557525?
Users can mitigate the risks of REDHAT-BUG-557525 by ensuring their screensaver settings require authentication and by applying the latest software updates.