CVE-2007-1859

XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.
References
Link Resource
http://osvdb.org/35531
http://secunia.com/advisories/25065 Vendor Advisory
http://secunia.com/advisories/25105 Vendor Advisory
http://secunia.com/advisories/25116 Vendor Advisory
http://secunia.com/advisories/25118 Vendor Advisory
http://secunia.com/advisories/25119 Vendor Advisory
http://secunia.com/advisories/25225 Vendor Advisory
http://secunia.com/advisories/25610
http://security.gentoo.org/glsa/glsa-200705-14.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:097
http://www.novell.com/linux/security/advisories/2007_9_sr.html
http://www.redhat.com/support/errata/RHSA-2007-0322.html Patch Vendor Advisory
http://www.securityfocus.com/bid/23783
http://www.securitytracker.com/id?1017996
http://www.ubuntu.com/usn/usn-474-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/34054
https://issues.rpath.com/browse/RPL-1293
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11459
http://osvdb.org/35531
http://secunia.com/advisories/25065 Vendor Advisory
http://secunia.com/advisories/25105 Vendor Advisory
http://secunia.com/advisories/25116 Vendor Advisory
http://secunia.com/advisories/25118 Vendor Advisory
http://secunia.com/advisories/25119 Vendor Advisory
http://secunia.com/advisories/25225 Vendor Advisory
http://secunia.com/advisories/25610
http://security.gentoo.org/glsa/glsa-200705-14.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:097
http://www.novell.com/linux/security/advisories/2007_9_sr.html
http://www.redhat.com/support/errata/RHSA-2007-0322.html Patch Vendor Advisory
http://www.securityfocus.com/bid/23783
http://www.securitytracker.com/id?1017996
http://www.ubuntu.com/usn/usn-474-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/34054
https://issues.rpath.com/browse/RPL-1293
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11459
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:redhat:enterprise_linux:2.1:*:advanced_server:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:2.1:*:enterprise_server:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:2.1:*:workstation:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:3.0:*:advanced_servers:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:3.0:*:enterprise_server:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:3.0:*:workstation:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:4.0:*:advanced_server:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:4.0:*:enterprise_server:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:4.0:*:workstation:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:3.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:linux_advanced_workstation:2.1:*:itanium:*:*:*:*:*
cpe:2.3:a:xscreensaver:xscreensaver:4.10:*:*:*:*:*:*:*

History

21 Nov 2024, 00:29

Type Values Removed Values Added
References () http://osvdb.org/35531 - () http://osvdb.org/35531 -
References () http://secunia.com/advisories/25065 - Vendor Advisory () http://secunia.com/advisories/25065 - Vendor Advisory
References () http://secunia.com/advisories/25105 - Vendor Advisory () http://secunia.com/advisories/25105 - Vendor Advisory
References () http://secunia.com/advisories/25116 - Vendor Advisory () http://secunia.com/advisories/25116 - Vendor Advisory
References () http://secunia.com/advisories/25118 - Vendor Advisory () http://secunia.com/advisories/25118 - Vendor Advisory
References () http://secunia.com/advisories/25119 - Vendor Advisory () http://secunia.com/advisories/25119 - Vendor Advisory
References () http://secunia.com/advisories/25225 - Vendor Advisory () http://secunia.com/advisories/25225 - Vendor Advisory
References () http://secunia.com/advisories/25610 - () http://secunia.com/advisories/25610 -
References () http://security.gentoo.org/glsa/glsa-200705-14.xml - () http://security.gentoo.org/glsa/glsa-200705-14.xml -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2007:097 - () http://www.mandriva.com/security/advisories?name=MDKSA-2007:097 -
References () http://www.novell.com/linux/security/advisories/2007_9_sr.html - () http://www.novell.com/linux/security/advisories/2007_9_sr.html -
References () http://www.redhat.com/support/errata/RHSA-2007-0322.html - Patch, Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2007-0322.html - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/23783 - () http://www.securityfocus.com/bid/23783 -
References () http://www.securitytracker.com/id?1017996 - () http://www.securitytracker.com/id?1017996 -
References () http://www.ubuntu.com/usn/usn-474-1 - () http://www.ubuntu.com/usn/usn-474-1 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/34054 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/34054 -
References () https://issues.rpath.com/browse/RPL-1293 - () https://issues.rpath.com/browse/RPL-1293 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11459 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11459 -

Information

Published : 2007-05-02 20:19

Updated : 2024-11-21 00:29


NVD link : CVE-2007-1859

Mitre link : CVE-2007-1859

CVE.ORG link : CVE-2007-1859


JSON object : View

Products Affected

xscreensaver

  • xscreensaver

redhat

  • enterprise_linux_desktop
  • linux_advanced_workstation
  • enterprise_linux
CWE
CWE-287

Improper Authentication