CVE-2007-1859Improper Authentication in Xscreensaver

Severity
4.7MEDIUMNVD
NVD4.6OSV4.6
EPSS
0.1%
top 75.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 1

Description

XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages5 packages

debiandebian/xscreensaver< xscreensaver 5.03-1 (bookworm)
Debianxscreensaver/xscreensaver< 5.03-1+3
debiandebian/gnome-screensaver< gnome-screensaver 2.22.2-1 (bookworm)
NVDgnome/screensaver2.20.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-x3jq-r6gp-49qf: gnome-screensaver before 22022-05-01
GHSA
GHSA-fr4x-26r9-jx2p: XScreenSaver 42022-05-01
OSV
CVE-2008-0887: gnome-screensaver before 22008-04-06
OSV
CVE-2007-1859: XScreenSaver 42007-05-02

📋Vendor Advisories

5
Red Hat
gnome-screensaver using NIS auth will unlock if NIS goes away2008-04-02
Debian
CVE-2008-0887: gnome-screensaver - gnome-screensaver before 2.22.1, when a remote authentication server is enabled,...2008
Ubuntu
xscreensaver vulnerability2007-06-12
Red Hat
xscreensaver authentication bypass2007-05-03
Debian
CVE-2007-1859: xscreensaver - XScreenSaver 4.10, when using a remote directory service for credentials, does n...2007

💬Community

1
Bugzilla
CVE-2007-1859 xscreensaver authentication bypass2007-04-18
CVE-2007-1859 — Improper Authentication in Xscreensaver | cvebase