SB2019112726 - Missing Authentication for Critical Function in Debian Linux
Published: November 27, 2019 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Authentication for Critical Function (CVE-ID: CVE-2011-2187)
The vulnerability allows a local authenticated user to execute arbitrary code.
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
Remediation
Install update from vendor's website.
References
- https://access.redhat.com/security/cve/cve-2011-2187
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627382
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2187
- https://security-tracker.debian.org/tracker/CVE-2011-2187
- https://www.jwz.org/xscreensaver/changelog.html
- https://www.openwall.com/lists/oss-security/2011/06/06/17