gnome-screensaver Lets Local Users Bypass the Password
|
|
SecurityTracker Alert ID: 1019749
|
|
SecurityTracker URL: http://securitytracker.com/id?1019749
|
|
CVE Reference: CVE-2008-0887
(Links to External Site)
|
Date: Apr 2 2008
|
Impact: User access via local system
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 2.22.1
|
Description: A vulnerability was reported in gnome-screensaver. A local user can bypass the login function.
When the system uses a remote NIS server for authentication, a physically local user that can cause a network outage can cause gnome-screensaver to crash and unlock the screen.
Alan Matsuoka reported this vulnerability.
|
Impact: A physically local user can bypass the screensaver password function.
|
Solution: The vendor has issued a fixed version (2.22.1).
|
Vendor URL: live.gnome.org/GnomeScreensaver/ (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Linux (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 2 Apr 2008 11:48:45 -0500
Subject: GNOME screensaver
|
Red Hat reported:
A flaw was found in the way gnome-screensaver verified user passwords. When
a system used a remote directory service for login credentials, a local
attacker able to cause a network outage could cause gnome-screensaver to
crash, unlocking the screen. (CVE-2008-0887)
|
|