CVE-2007-3920

GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.html
http://secunia.com/advisories/27381 Patch Vendor Advisory
http://secunia.com/advisories/28627
http://secunia.com/advisories/30329
http://secunia.com/advisories/30715
http://www.redhat.com/support/errata/RHSA-2008-0485.html
http://www.securityfocus.com/bid/26188 Patch
http://www.ubuntu.com/usn/usn-537-1 Patch
http://www.ubuntu.com/usn/usn-537-2
https://bugzilla.redhat.com/show_bug.cgi?id=357071
https://bugzilla.redhat.com/show_bug.cgi?id=363061
https://exchange.xforce.ibmcloud.com/vulnerabilities/37410
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10192
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00811.html
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00841.html
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.html
http://secunia.com/advisories/27381 Patch Vendor Advisory
http://secunia.com/advisories/28627
http://secunia.com/advisories/30329
http://secunia.com/advisories/30715
http://www.redhat.com/support/errata/RHSA-2008-0485.html
http://www.securityfocus.com/bid/26188 Patch
http://www.ubuntu.com/usn/usn-537-1 Patch
http://www.ubuntu.com/usn/usn-537-2
https://bugzilla.redhat.com/show_bug.cgi?id=357071
https://bugzilla.redhat.com/show_bug.cgi?id=363061
https://exchange.xforce.ibmcloud.com/vulnerabilities/37410
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10192
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00811.html
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00841.html
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:ubuntu:ubuntu_linux:7.10:*:amd64:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:7.10:*:i386:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:7.10:*:powerpc:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:7.10:*:sparc:*:*:*:*:*
OR cpe:2.3:a:compiz:compiz:*:*:*:*:*:*:*:*
cpe:2.3:a:gnome:screensaver:2.20:*:*:*:*:*:*:*

History

21 Nov 2024, 00:34

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.html - () http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.html -
References () http://secunia.com/advisories/27381 - Patch, Vendor Advisory () http://secunia.com/advisories/27381 - Patch, Vendor Advisory
References () http://secunia.com/advisories/28627 - () http://secunia.com/advisories/28627 -
References () http://secunia.com/advisories/30329 - () http://secunia.com/advisories/30329 -
References () http://secunia.com/advisories/30715 - () http://secunia.com/advisories/30715 -
References () http://www.redhat.com/support/errata/RHSA-2008-0485.html - () http://www.redhat.com/support/errata/RHSA-2008-0485.html -
References () http://www.securityfocus.com/bid/26188 - Patch () http://www.securityfocus.com/bid/26188 - Patch
References () http://www.ubuntu.com/usn/usn-537-1 - Patch () http://www.ubuntu.com/usn/usn-537-1 - Patch
References () http://www.ubuntu.com/usn/usn-537-2 - () http://www.ubuntu.com/usn/usn-537-2 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=357071 - () https://bugzilla.redhat.com/show_bug.cgi?id=357071 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=363061 - () https://bugzilla.redhat.com/show_bug.cgi?id=363061 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/37410 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/37410 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10192 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10192 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00811.html - () https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00811.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00841.html - () https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00841.html -

Information

Published : 2007-10-29 21:46

Updated : 2024-11-21 00:34


NVD link : CVE-2007-3920

Mitre link : CVE-2007-3920

CVE.ORG link : CVE-2007-3920


JSON object : View

Products Affected

ubuntu

  • ubuntu_linux

gnome

  • screensaver

compiz

  • compiz