Vulnerability Name: | CVE-2012-0064 (CCN-72459) |
Assigned: | 2011-12-07 |
Published: | 2012-01-19 |
Updated: | 2014-02-11 |
Summary: | xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.
|
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) 1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-264
|
Vulnerability Consequences: | Bypass Security |
References: | Source: MITRE Type: CNA CVE-2012-0064
Source: CCN Type: Gu1's Web site Bypass screensaver/locker program on xorg 1.11 and up
Source: MISC Type: UNKNOWN http://gu1.aeroxteam.fr/2012/01/19/bypass-screensaver-locker-program-xorg-111-and-up/
Source: MLIST Type: UNKNOWN [xorg-announce] 20120119 xkeyboard-config 2.5
Source: MLIST Type: UNKNOWN [xorg-devel] 20120119 [PATCH SECURITY] XKB: Workaround for CVE-2012-0064: Stop calling UngrabAllDevices().
Source: CCN Type: SA47566 X.Org Grab-Breaking Keybinding Security Bypass Weakness
Source: SECTRACK Type: UNKNOWN 1026549
Source: MISC Type: UNKNOWN http://who-t.blogspot.com/2012/01/xkb-breaking-grabs-cve-2012-0064.html
Source: MLIST Type: UNKNOWN [oss-security] 20120118 Re: Screen locking programs on Xorg 1.11
Source: OSVDB Type: UNKNOWN 78445
Source: CCN Type: OSVDB ID: 78445 X.Org X Window System (X11) Grab-Breaking Keybinding Screensaver Lock Bypass
Source: CCN Type: BID-51562 X.Org XServer ScreenSaver Lock Bypass Vulnerability
Source: CCN Type: X.Org Foundation Web site X.Org Wiki - Home
Source: CONFIRM Type: Vendor Advisory http://www.x.org/wiki/Development/Security/
Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=783039
Source: XF Type: UNKNOWN xorg-screensaver-security-bypass(72459)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:x:x.org_x11:1.0:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:3.0:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:4.0:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:5.0:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:6.0:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:6.1:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:6.3:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:6.4:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:6.5.1:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:6.6:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:6.7:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:6.8:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:6.8.1:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:6.8.2:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:6.9.0:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:7.0:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:7.1:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:7.2:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:7.3:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:7.4:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:7.5:*:*:*:*:*:*:*OR cpe:/a:x:x.org_x11:*:rc1:*:*:*:*:*:* (Version <= 7.5)OR cpe:/a:xkeyboard_config_project:xkeyboard-config:2.0:*:*:*:*:*:*:*OR cpe:/a:xkeyboard_config_project:xkeyboard-config:2.1:*:*:*:*:*:*:*OR cpe:/a:xkeyboard_config_project:xkeyboard-config:2.2:*:*:*:*:*:*:*OR cpe:/a:xkeyboard_config_project:xkeyboard-config:2.3:*:*:*:*:*:*:*OR cpe:/a:xkeyboard_config_project:xkeyboard-config:*:*:*:*:*:*:*:* (Version <= 2.4) Configuration CCN 1: cpe:/a:x.org:x11:1.11:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |