SB2015113004 - Permissions, Privileges, and Access Controls in xscreensaver (Alpine package)
Published: November 30, 2015
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2015-8025)
The vulnerability allows a local non-authenticated attacker to manipulate data.
driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.
Remediation
Install update from vendor's website.