Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.840218
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-688-1)
Summary:The remote host is missing an update for the 'compiz-fusion-plugins-main' package(s) announced via the USN-688-1 advisory.
Description:Summary:
The remote host is missing an update for the 'compiz-fusion-plugins-main' package(s) announced via the USN-688-1 advisory.

Vulnerability Insight:
It was discovered that the Expo plugin for Compiz did not correctly
restrict the screensaver window from being moved with the mouse. A local
attacker could use the mouse to move the screensaver off the screen and
gain access to the locked desktop session underneath. Default installs
of Ubuntu were not vulnerable as Expo does not come pre-configured with
mouse bindings.

Affected Software/OS:
'compiz-fusion-plugins-main' package(s) on Ubuntu 7.10, Ubuntu 8.04, Ubuntu 8.10.

Solution:
Please install the updated package(s).

CVSS Score:
6.2

CVSS Vector:
AV:L/AC:H/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-6514
BugTraq ID: 32712
http://www.securityfocus.com/bid/32712
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00860.html
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00878.html
https://bugs.launchpad.net/ubuntu/+source/compiz-fusion-plugins-main/+bug/247088
http://secunia.com/advisories/33077
http://secunia.com/advisories/34465
XForce ISS Database: compizfusion-expo-security-bypass(47172)
https://exchange.xforce.ibmcloud.com/vulnerabilities/47172
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.