XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, as demonstrated by Thunderbird new-mail notifications.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://sunsolve.sun.com/search/document.do?assetkey=1-21-120094-22-1 | patch vendor advisory |
http://www.vupen.com/english/advisories/2009/0978 | vdb entry |
http://securitytracker.com/id?1022009 | vdb entry |
http://www.securityfocus.com/bid/34421 | vdb entry |
http://sunsolve.sun.com/search/document.do?assetkey=1-66-255308-1 | patch vendor advisory |