lists.openwall.net   lists  /  announce  john-users  owl-users  popa3d-users  /  xvendor  oss-security  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4 
Open Source and information security mailing list archives
 
This website is powered by Openwall GNU/*/Linux security-enhanced OS
[<prev] [next>] [month] [year] [list]
Date: Thu, 03 May 2007 15:43:05 -0400
From: rPath Update Announcements <announce-noreply@...th.com>
To: security-announce@...ts.rpath.com,
	update-announce@...ts.rpath.com
Subject: rPSA-2007-0088-1 xscreensaver

rPath Security Advisory: 2007-0088-1
Published: 2007-05-03
Products: rPath Linux 1
Rating: Major
Exposure Level Classification:
    Local User Deterministic Weakness
Updated Versions:
    xscreensaver=/conary.rpath.com@...:devel//1/4.22-1.2-1

References:
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1859
    https://issues.rpath.com/browse/RPL-1293

Description:
    Previous versions of xscreensaver are vulnerable to an attack that
    requires that the attacker have physical access.  If the system is
    configured to use remote directory service for login credentials,
    an attacker who can cause or take advantage of a network failure
    can cause the xscreensaver process to crash, unlocking the screen,
    and allowing the attacker unrestricted access to the system as the
    logged-in user.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux