| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.67048 |
| Kategorie: | Ubuntu Local Security Checks |
| Titel: | Ubuntu USN-907-1 (gnome-screensaver) |
| Zusammenfassung: | Ubuntu USN-907-1 (gnome-screensaver) |
| Beschreibung: | The remote host is missing an update to gnome-screensaver announced via advisory USN-907-1. Details follow: It was discovered that gnome-screensaver did not correctly lock all screens when monitors get hotplugged. An attacker with physical access could use this flaw to gain access to a locked session. (CVE-2010-0285) It was discovered that gnome-screensaver did not correctly handle keyboard grab when monitors get hotplugged. An attacker with physical access could use this flaw to gain access to a locked session. This issue only affected Ubuntu 9.10. (CVE-2010-0422) Solution: The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.10: gnome-screensaver 2.24.0-0ubuntu2.1 Ubuntu 9.04: gnome-screensaver 2.24.0-0ubuntu6.1 Ubuntu 9.10: gnome-screensaver 2.28.0-0ubuntu3.5 After a standard system upgrade you need to restart your session to effect the necessary changes. http://www.securityspace.com/smysecure/catid.html?in=USN-907-1 Risk factor : High |
| Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-0285 http://www.mandriva.com/security/advisories?name=MDVSA-2011:093 BugTraq ID: 38254 http://www.securityfocus.com/bid/38254 XForce ISS Database: screensaver-monitor-setup-sec-bypass(56366) http://xforce.iss.net/xforce/xfdb/56366 Common Vulnerability Exposure (CVE) ID: CVE-2010-0422 http://marc.info/?l=oss-security&m=126601292400764&w=2 http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035115.html BugTraq ID: 38248 http://www.securityfocus.com/bid/38248 http://secunia.com/advisories/38565 http://secunia.com/advisories/38583 XForce ISS Database: gnome-screensaver-monitor-sec-bypass(56364) http://xforce.iss.net/xforce/xfdb/56364 |
| Copyright | Copyright (c) 2010 E-Soft Inc. http://www.securityspace.com |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|