xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2011-2187 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2187 | issue tracking exploit third party advisory |
https://access.redhat.com/security/cve/cve-2011-2187 | third party advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627382 | third party advisory exploit |
https://www.openwall.com/lists/oss-security/2011/06/06/17 | third party advisory mailing list |
https://www.jwz.org/xscreensaver/changelog.html | release notes vendor advisory |