| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.67048 |
| Category: | Ubuntu Local Security Checks |
| Title: | Ubuntu USN-907-1 (gnome-screensaver) |
| Summary: | Ubuntu USN-907-1 (gnome-screensaver) |
| Description: | The remote host is missing an update to gnome-screensaver announced via advisory USN-907-1. Details follow: It was discovered that gnome-screensaver did not correctly lock all screens when monitors get hotplugged. An attacker with physical access could use this flaw to gain access to a locked session. (CVE-2010-0285) It was discovered that gnome-screensaver did not correctly handle keyboard grab when monitors get hotplugged. An attacker with physical access could use this flaw to gain access to a locked session. This issue only affected Ubuntu 9.10. (CVE-2010-0422) Solution: The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.10: gnome-screensaver 2.24.0-0ubuntu2.1 Ubuntu 9.04: gnome-screensaver 2.24.0-0ubuntu6.1 Ubuntu 9.10: gnome-screensaver 2.28.0-0ubuntu3.5 After a standard system upgrade you need to restart your session to effect the necessary changes. http://www.securityspace.com/smysecure/catid.html?in=USN-907-1 Risk factor : High |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-0285 http://www.mandriva.com/security/advisories?name=MDVSA-2011:093 BugTraq ID: 38254 http://www.securityfocus.com/bid/38254 XForce ISS Database: screensaver-monitor-setup-sec-bypass(56366) http://xforce.iss.net/xforce/xfdb/56366 Common Vulnerability Exposure (CVE) ID: CVE-2010-0422 http://marc.info/?l=oss-security&m=126601292400764&w=2 http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035115.html BugTraq ID: 38248 http://www.securityfocus.com/bid/38248 http://secunia.com/advisories/38565 http://secunia.com/advisories/38583 XForce ISS Database: gnome-screensaver-monitor-sec-bypass(56364) http://xforce.iss.net/xforce/xfdb/56364 |
| Copyright | Copyright (c) 2010 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|