CVE-2007-1859

NameCVE-2007-1859
DescriptionXScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs433964

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xscreensaver (PTS)jessie, jessie (lts)5.30-1+deb8u2fixed
stretch5.36-1fixed
buster5.42+dfsg1-1fixed
bullseye5.45+dfsg1-2fixed
bookworm6.06+dfsg1-3+deb12u1fixed
sid, trixie6.08+dfsg1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xscreensaversource(unstable)5.03-1low433964

Notes

[etch] - xscreensaver <no-dsa> (Minor issue, requires attacker with high level of control, see #433964)
[sarge] - xscreensaver <no-dsa> (Minor issue, requires attacker with high level of control, see #433964)

Search for package or bug name: Reporting problems