Vulnerability Name: | CVE-2007-3920 (CCN-37410) | ||||||||||||||||||||||||||||
Assigned: | 2007-10-19 | ||||||||||||||||||||||||||||
Published: | 2007-10-19 | ||||||||||||||||||||||||||||
Updated: | 2017-09-29 | ||||||||||||||||||||||||||||
Summary: | GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.2 Medium (CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C) 4.6 Medium (Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2007-3920 Source: SUSE Type: UNKNOWN SUSE-SA:2008:027 Source: CCN Type: GNOME Screensaver Web site GnomeScreensaver Source: CCN Type: RHSA-2008-0485 Low: compiz security update Source: SECUNIA Type: Patch, Vendor Advisory 27381 Source: SECUNIA Type: UNKNOWN 28627 Source: SECUNIA Type: UNKNOWN 30329 Source: SECUNIA Type: UNKNOWN 30715 Source: REDHAT Type: UNKNOWN RHSA-2008:0485 Source: BID Type: Patch 26188 Source: CCN Type: BID-26188 Gnome-Screensaver With Compiz Lock Bypass Vulnerability Source: CCN Type: USN-537-1 gnome-screensaver vulnerability Source: UBUNTU Type: Patch USN-537-1 Source: CCN Type: USN-537-2 Compiz vulnerability Source: UBUNTU Type: UNKNOWN USN-537-2 Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=357071 Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=363061 Source: XF Type: UNKNOWN gnomescreensaver-compiz-security-bypass(37410) Source: XF Type: UNKNOWN gnomescreensaver-compiz-security-bypass(37410) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10192 Source: FEDORA Type: UNKNOWN FEDORA-2008-0930 Source: FEDORA Type: UNKNOWN FEDORA-2008-0956 Source: SUSE Type: SUSE-SA:2008:027 X.org security problems | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |