5
CVSSv2

CVE-2007-5585

Published: 19/10/2007 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

xscreensaver 5.03 and previous versions, when running without xscreensaver-gl-extras (GL extras) installed, crashes when /usr/bin/xscreensaver-gl-helper does not exist and a user attempts to unlock the screen, which allows attackers with physical access to gain access to the locked session.

Vulnerable Product Search on Vulmon Subscribe to Product

xscreensaver xscreensaver 5.03

Vendor Advisories

Debian Bug report logs - #448157 CVE-2007-5585 authentication bypass Package: xscreensaver; Maintainer for xscreensaver is Tormod Volden <debiantormod@gmailcom>; Source for xscreensaver is src:xscreensaver (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Fri, 26 Oct 2007 13:15:02 UTC Severity: ...