PDA

View Full Version : USN-537-1: gnome-screensaver vulnerability



rss-bot
October 24th, 2007, 04:30 AM
Referenced CVEs:
CVE-2007-3920


Description:
================================================== ========= Ubuntu Security Notice USN-537-1 October 23, 2007 gnome-screensaver vulnerability CVE-2007-3920 ================================================== ========= A security issue affects the following Ubuntu releases: Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 7.10: gnome-screensaver 2.20.0-0ubuntu4.2 After a standard system upgrade you need to restart your session to affect the necessary changes. Details follow: Jens Askengren discovered that gnome-screensaver became confused when running under Compiz, and could lose keyboard lock focus. A local attacker could exploit this to bypass the user's locked screen saver.





More... (http://www.ubuntu.com/usn/usn-537-1)