Back

MEDIUM

xscreensaver authentication bypass

Published May 2, 2007

Description

XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 2, 2007
Updated Aug 7, 2024
Reserved Apr 4, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date May 3, 2007