mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content and possibly control applications. By unplugging and re-plugging or power-cycling external output devices (such as additionally attached graphical outputs via HDMI, VGA, DVI, etc.) the content of a screensaver-locked session can be revealed. In some scenarios, the attacker can execute applications, such as by clicking with a mouse.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/mate-desktop/mate-screensaver/pull/167 | third party advisory patch |
https://github.com/mate-desktop/mate-screensaver/issues/170 | third party advisory |
https://github.com/mate-desktop/mate-screensaver/issues/152 | patch third party advisory exploit |
https://github.com/mate-desktop/mate-screensaver/issues/155 | third party advisory exploit |