Vulnerability Name:
CVE-2012-0064 (CCN-72459)
Assigned:
2011-12-07
Published:
2012-01-19
Updated:
2014-02-11
Summary:
xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.
CVSS v3 Severity:
4.0 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
)
Exploitability Metrics:
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
Low
Availibility (A):
None
CVSS v2 Severity:
4.6 Medium
(CVSS v2 Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P
)
3.4 Low
(Temporal CVSS v2 Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
2.1 Low
(CCN CVSS v2 Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:N
)
1.6 Low
(CCN Temporal CVSS v2 Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
Partial
Availibility (A):
None
Vulnerability Type:
CWE-264
Vulnerability Consequences:
Bypass Security
References:
Source: MITRE
Type: CNA
CVE-2012-0064
Source: CCN
Type: Gu1's Web site
Bypass screensaver/locker program on xorg 1.11 and up
Source: MISC
Type: UNKNOWN
http://gu1.aeroxteam.fr/2012/01/19/bypass-screensaver-locker-program-xorg-111-and-up/
Source: MLIST
Type: UNKNOWN
[xorg-announce] 20120119 xkeyboard-config 2.5
Source: MLIST
Type: UNKNOWN
[xorg-devel] 20120119 [PATCH SECURITY] XKB: Workaround for CVE-2012-0064: Stop calling UngrabAllDevices().
Source: CCN
Type: SA47566
X.Org Grab-Breaking Keybinding Security Bypass Weakness
Source: SECTRACK
Type: UNKNOWN
1026549
Source: MISC
Type: UNKNOWN
http://who-t.blogspot.com/2012/01/xkb-breaking-grabs-cve-2012-0064.html
Source: MLIST
Type: UNKNOWN
[oss-security] 20120118 Re: Screen locking programs on Xorg 1.11
Source: OSVDB
Type: UNKNOWN
78445
Source: CCN
Type: OSVDB ID: 78445
X.Org X Window System (X11) Grab-Breaking Keybinding Screensaver Lock Bypass
Source: CCN
Type: BID-51562
X.Org XServer ScreenSaver Lock Bypass Vulnerability
Source: CCN
Type: X.Org Foundation Web site
X.Org Wiki - Home
Source: CONFIRM
Type: Vendor Advisory
http://www.x.org/wiki/Development/Security/
Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=783039
Source: XF
Type: UNKNOWN
xorg-screensaver-security-bypass(72459)
Vulnerable Configuration:
Configuration 1
:
cpe:/a:x:x.org_x11:1.0:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:3.0:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:4.0:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:5.0:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:6.0:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:6.1:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:6.3:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:6.4:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:6.5.1:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:6.6:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:6.7:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:6.8:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:6.8.1:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:6.8.2:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:6.9.0:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:7.0:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:7.1:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:7.2:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:7.3:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:7.4:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:7.5:*:*:*:*:*:*:*
OR
cpe:/a:x:x.org_x11:*:rc1:*:*:*:*:*:*
(Version <= 7.5)
OR
cpe:/a:xkeyboard_config_project:xkeyboard-config:2.0:*:*:*:*:*:*:*
OR
cpe:/a:xkeyboard_config_project:xkeyboard-config:2.1:*:*:*:*:*:*:*
OR
cpe:/a:xkeyboard_config_project:xkeyboard-config:2.2:*:*:*:*:*:*:*
OR
cpe:/a:xkeyboard_config_project:xkeyboard-config:2.3:*:*:*:*:*:*:*
OR
cpe:/a:xkeyboard_config_project:xkeyboard-config:*:*:*:*:*:*:*:*
(Version <= 2.4)
Configuration CCN 1
:
cpe:/a:x.org:x11:1.11:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
x
x.org x11 1.0
x
x.org x11 3.0
x
x.org x11 4.0
x
x.org x11 5.0
x
x.org x11 6.0
x
x.org x11 6.1
x
x.org x11 6.3
x
x.org x11 6.4
x
x.org x11 6.5.1
x
x.org x11 6.6
x
x.org x11 6.7
x
x.org x11 6.8
x
x.org x11 6.8.1
x
x.org x11 6.8.2
x
x.org x11 6.9.0
x
x.org x11 7.0
x
x.org x11 7.1
x
x.org x11 7.2
x
x.org x11 7.3
x
x.org x11 7.4
x
x.org x11 7.5
x
x.org x11 * rc1
xkeyboard_config_project
xkeyboard-config 2.0
xkeyboard_config_project
xkeyboard-config 2.1
xkeyboard_config_project
xkeyboard-config 2.2
xkeyboard_config_project
xkeyboard-config 2.3
xkeyboard_config_project
xkeyboard-config *
x.org
x11 1.11