The default configuration in gnome-screensaver 3.5.4 up to and including 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prevents the program from starting automatically after login and allows physically proximate malicious users to bypass screen locking and access an unattended workstation.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gnome gnome screensaver 3.5.4 |
||
gnome gnome screensaver 3.5.5 |
||
gnome gnome screensaver 3.6.0 |