Vulnerability Name: | CVE-2007-1859 (CCN-34054) | ||||||||||||||||
Assigned: | 2007-05-02 | ||||||||||||||||
Published: | 2007-05-02 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication. | ||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-287 | ||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2007-1859 Source: OSVDB Type: UNKNOWN 35531 Source: CCN Type: RHSA-2007-0322 Important: xscreensaver security update Source: CCN Type: SA25065 XScreenSaver "getpwuid()" Authentication Bypass Weakness Source: SECUNIA Type: Vendor Advisory 25065 Source: SECUNIA Type: Vendor Advisory 25105 Source: SECUNIA Type: Vendor Advisory 25116 Source: SECUNIA Type: Vendor Advisory 25118 Source: SECUNIA Type: Vendor Advisory 25119 Source: SECUNIA Type: Vendor Advisory 25225 Source: SECUNIA Type: UNKNOWN 25610 Source: GENTOO Type: UNKNOWN GLSA-200705-14 Source: CCN Type: SECTRACK ID: 1017996 XScreenSaver LDAP Authentication Error Lets Physically Local Users Bypass the Password Feature Source: CCN Type: ASA-2007-264 XScreenSaver security update (RHSA-2007-0322) Source: CCN Type: GLSA-200705-14 XScreenSaver: Privilege escalation Source: CCN Type: XScreenSaver Web site XScreenSaver Source: MANDRIVA Type: UNKNOWN MDKSA-2007:097 Source: SUSE Type: UNKNOWN SUSE-SR:2007:009 Source: CCN Type: OSVDB ID: 35531 XScreenSaver getpwuid() Failed Network Authentication Screen Lock Bypass Source: REDHAT Type: Patch, Vendor Advisory RHSA-2007:0322 Source: BID Type: UNKNOWN 23783 Source: CCN Type: BID-23783 Xscreensaver Local Denial Of Service Vulnerability Source: SECTRACK Type: UNKNOWN 1017996 Source: CCN Type: USN-474-1 xscreensaver vulnerability Source: UBUNTU Type: UNKNOWN USN-474-1 Source: CCN Type: Red Hat Bugzilla Bug 237003 CVE-2007-1859 xscreensaver authentication bypass Source: XF Type: UNKNOWN xscreensaver-getpwuid-authentication-bypass(34054) Source: XF Type: UNKNOWN xscreensaver-getpwuid-authentication-bypass(34054) Source: CONFIRM Type: UNKNOWN https://issues.rpath.com/browse/RPL-1293 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11459 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |