7.5
CVSSv3

CVE-2016-6866

Published: 15/02/2017 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

slock allows malicious users to bypass the screen lock via vectors involving an invalid password hash, which triggers a NULL pointer dereference and crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

suckless slock

fedoraproject fedora 25

fedoraproject fedora 24

Vendor Advisories

A null pointer dereference vulnerability has been discovered in the screen locking application slock It calls crypt(3) and uses the return value for strcmp(3) without checking to see if the return value of crypt(3) was a NULL pointer If the hash returned by (getspnam()->sp_pwdp) is invalid, crypt(3) will return NULL and set errno to EINVAL Th ...