SB2019112726 - Missing Authentication for Critical Function in Debian Linux



SB2019112726 - Missing Authentication for Critical Function in Debian Linux

Published: November 27, 2019 Updated: August 8, 2020

Security Bulletin ID SB2019112726
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Missing Authentication for Critical Function (CVE-ID: CVE-2011-2187)

The vulnerability allows a local authenticated user to execute arbitrary code.

xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.


Remediation

Install update from vendor's website.