CVE-2007-1859
xscreensaver authentication bypass
Severity Score
4.6
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.
XScreenSaver versión 4.10, cuando está usando un servicio de directorio remoto para credenciales, no maneja apropiadamente los resultados de la función getpwuid en el archivo drivers/lock.c cuando no hay conectividad de red, lo que causa que XScreenSaver bloquee y desbloquee la pantalla y permita a usuarios locales omitir la autenticación.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-04-04 CVE Reserved
- 2007-05-02 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (20)
URL | Tag | Source |
---|---|---|
http://osvdb.org/35531 | Vdb Entry | |
http://secunia.com/advisories/25610 | Third Party Advisory | |
http://www.securityfocus.com/bid/23783 | Vdb Entry | |
http://www.securitytracker.com/id?1017996 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34054 | Vdb Entry | |
https://issues.rpath.com/browse/RPL-1293 | X_refsource_confirm | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11459 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.redhat.com/support/errata/RHSA-2007-0322.html | 2017-10-11 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/25065 | 2017-10-11 | |
http://secunia.com/advisories/25105 | 2017-10-11 | |
http://secunia.com/advisories/25116 | 2017-10-11 | |
http://secunia.com/advisories/25118 | 2017-10-11 | |
http://secunia.com/advisories/25119 | 2017-10-11 | |
http://secunia.com/advisories/25225 | 2017-10-11 | |
http://security.gentoo.org/glsa/glsa-200705-14.xml | 2017-10-11 | |
http://www.mandriva.com/security/advisories?name=MDKSA-2007:097 | 2017-10-11 | |
http://www.novell.com/linux/security/advisories/2007_9_sr.html | 2017-10-11 | |
http://www.ubuntu.com/usn/usn-474-1 | 2017-10-11 | |
https://access.redhat.com/security/cve/CVE-2007-1859 | 2007-05-02 | |
https://bugzilla.redhat.com/show_bug.cgi?id=237003 | 2007-05-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xscreensaver Search vendor "Xscreensaver" | Xscreensaver Search vendor "Xscreensaver" for product "Xscreensaver" | 4.10 Search vendor "Xscreensaver" for product "Xscreensaver" and version "4.10" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 2.1 Search vendor "Redhat" for product "Enterprise Linux" and version "2.1" | advanced_server |
Safe
|
Xscreensaver Search vendor "Xscreensaver" | Xscreensaver Search vendor "Xscreensaver" for product "Xscreensaver" | 4.10 Search vendor "Xscreensaver" for product "Xscreensaver" and version "4.10" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 2.1 Search vendor "Redhat" for product "Enterprise Linux" and version "2.1" | enterprise_server |
Safe
|
Xscreensaver Search vendor "Xscreensaver" | Xscreensaver Search vendor "Xscreensaver" for product "Xscreensaver" | 4.10 Search vendor "Xscreensaver" for product "Xscreensaver" and version "4.10" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 2.1 Search vendor "Redhat" for product "Enterprise Linux" and version "2.1" | workstation |
Safe
|
Xscreensaver Search vendor "Xscreensaver" | Xscreensaver Search vendor "Xscreensaver" for product "Xscreensaver" | 4.10 Search vendor "Xscreensaver" for product "Xscreensaver" and version "4.10" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | advanced_servers |
Safe
|
Xscreensaver Search vendor "Xscreensaver" | Xscreensaver Search vendor "Xscreensaver" for product "Xscreensaver" | 4.10 Search vendor "Xscreensaver" for product "Xscreensaver" and version "4.10" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | enterprise_server |
Safe
|
Xscreensaver Search vendor "Xscreensaver" | Xscreensaver Search vendor "Xscreensaver" for product "Xscreensaver" | 4.10 Search vendor "Xscreensaver" for product "Xscreensaver" and version "4.10" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | workstation |
Safe
|
Xscreensaver Search vendor "Xscreensaver" | Xscreensaver Search vendor "Xscreensaver" for product "Xscreensaver" | 4.10 Search vendor "Xscreensaver" for product "Xscreensaver" and version "4.10" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 4.0 Search vendor "Redhat" for product "Enterprise Linux" and version "4.0" | advanced_server |
Safe
|
Xscreensaver Search vendor "Xscreensaver" | Xscreensaver Search vendor "Xscreensaver" for product "Xscreensaver" | 4.10 Search vendor "Xscreensaver" for product "Xscreensaver" and version "4.10" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 4.0 Search vendor "Redhat" for product "Enterprise Linux" and version "4.0" | enterprise_server |
Safe
|
Xscreensaver Search vendor "Xscreensaver" | Xscreensaver Search vendor "Xscreensaver" for product "Xscreensaver" | 4.10 Search vendor "Xscreensaver" for product "Xscreensaver" and version "4.10" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 4.0 Search vendor "Redhat" for product "Enterprise Linux" and version "4.0" | workstation |
Safe
|
Xscreensaver Search vendor "Xscreensaver" | Xscreensaver Search vendor "Xscreensaver" for product "Xscreensaver" | 4.10 Search vendor "Xscreensaver" for product "Xscreensaver" and version "4.10" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 3.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "3.0" | - |
Safe
|
Xscreensaver Search vendor "Xscreensaver" | Xscreensaver Search vendor "Xscreensaver" for product "Xscreensaver" | 4.10 Search vendor "Xscreensaver" for product "Xscreensaver" and version "4.10" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 4.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "4.0" | - |
Safe
|
Xscreensaver Search vendor "Xscreensaver" | Xscreensaver Search vendor "Xscreensaver" for product "Xscreensaver" | 4.10 Search vendor "Xscreensaver" for product "Xscreensaver" and version "4.10" | - |
Affected
| in | Redhat Search vendor "Redhat" | Linux Advanced Workstation Search vendor "Redhat" for product "Linux Advanced Workstation" | 2.1 Search vendor "Redhat" for product "Linux Advanced Workstation" and version "2.1" | itanium |
Safe
|