The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/34465 | third party advisory |
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00878.html | vendor advisory |
http://bugzilla.gnome.org/show_bug.cgi?id=561567 | |
http://www.securityfocus.com/bid/32712 | vdb entry patch |
http://secunia.com/advisories/33077 | third party advisory vendor advisory |
http://gitweb.compiz-fusion.org/?p=fusion/plugins/expo%3Ba=commit%3Bh=f97a9fa6f0ad578f674d1f248bd7bef90e3260e0 | |
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00860.html | vendor advisory |
https://bugs.launchpad.net/ubuntu/+source/compiz-fusion-plugins-main/+bug/247088 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/47172 | vdb entry |