6.2
CVSSv2

CVE-2007-3920

Published: 29/10/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 552
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome screensaver 2.20

compiz compiz

Vendor Advisories

Debian Bug report logs - #449108 CVE-2007-3920: bypass password authentication Package: xserver-xorg-core; Maintainer for xserver-xorg-core is Debian X Strike Force <debian-x@listsdebianorg>; Source for xserver-xorg-core is src:xorg-server (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde&g ...
USN-537-1 fixed vulnerabilities in gnome-screensaver The fixes were incomplete, and only reduced the scope of the vulnerability, without fully solving it This update fixes related problems in compiz ...
Jens Askengren discovered that gnome-screensaver became confused when running under Compiz, and could lose keyboard lock focus A local attacker could exploit this to bypass the user’s locked screen saver ...