CVE-2007-1859
Published: 2 May 2007
XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.
Priority
Status
Package | Release | Status |
---|---|---|
xscreensaver Launchpad, Ubuntu, Debian |
dapper |
Released
(4.23-4ubuntu8.1)
|
edgy |
Released
(4.24-4ubuntu2.1)
|
|
feisty |
Released
(4.24-5ubuntu2.1)
|
|
upstream |
Needs triage
|