slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive information by pressing a button, which reveals the desktop and active windows.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://bugs.gentoo.org/show_bug.cgi?id=401645 | exploit |
http://www.openwall.com/lists/oss-security/2012/04/06/2 | mailing list |
http://www.openwall.com/lists/oss-security/2012/04/06/1 | mailing list exploit |
http://secunia.com/advisories/48700 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74666 | vdb entry |
http://www.osvdb.org/81035 | vdb entry |
http://www.securityfocus.com/bid/52922 | vdb entry |
http://hg.suckless.org/slock/rev/891a4984aba6 | patch exploit |
https://bugzilla.redhat.com/show_bug.cgi?id=786310 |