CVE-2006-0061

Publication date 6 November 2019

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
xlockmore 9.10 karmic
Fixed 5.22-1
9.04 jaunty
Fixed 5.22-1
8.10 intrepid
Fixed 5.22-1
8.04 LTS hardy
Fixed 5.22-1
7.10 gutsy
Fixed 5.22-1
7.04 feisty
Fixed 5.22-1
6.10 edgy
Fixed 5.22-1
6.06 LTS dapper Ignored end of life

Severity score breakdown

Parameter Value
Base score 9.8 · Critical
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H