Permissions, Privileges, and Access Controls in xscreensaver - CVE-2015-8025

 

Permissions, Privileges, and Access Controls in xscreensaver - CVE-2015-8025

Published: November 10, 2015 / Updated: July 28, 2020


Vulnerability identifier: #VU32377
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8025
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to manipulate data.

driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.


Affected software

xscreensaver
xscreensaver (Alpine package)

How to mitigate CVE-2015-8025

Install update from vendor's website.

xscreensaver - update to 5.34
xscreensaver (Alpine package) - update to 5.34-r0

External References

Related Security Bulletins