CVE-2007-3920
published 2007-10-29CVE-2007-3920: GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take…
PriorityP414medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.36%
28.2th percentile
GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| compiz | compiz_fusion | — | — |
| debian | gnome-screensaver | < gnome-screensaver 2.20.0-1.1 (bookworm) | gnome-screensaver 2.20.0-1.1 (bookworm) |
| debian | xorg-server | < gnome-screensaver 2.20.0-1.1 (bookworm) | gnome-screensaver 2.20.0-1.1 (bookworm) |
| gnome | screensaver | — | — |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080118-1 | 2:1.4.1~git20080118-1 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080118-1 | 2:1.4.1~git20080118-1 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080118-1 | 2:1.4.1~git20080118-1 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080118-1 | 2:1.4.1~git20080118-1 |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv4.6MEDIUM
vendor_redhat6.2MEDIUM
vendor_debian4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
compiz-fusion: Possible locked desktop access by using Expo plugin mouse shortcuts
vendor_redhat·2008-07-09·CVSS 6.2
CVE-2008-6514 [MEDIUM] compiz-fusion: Possible locked desktop access by using Expo plugin mouse shortcuts
compiz-fusion: Possible locked desktop access by using Expo plugin mouse shortcuts
The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.
Ubuntu
Compiz vulnerability
vendor_ubuntu·2007-11-02
CVE-2007-3920 Compiz vulnerability
Title: Compiz vulnerability
Summary: Compiz vulnerability
USN-537-1 fixed vulnerabilities in gnome-screensaver. The fixes were
incomplete, and only reduced the scope of the vulnerability, without
fully solving it. This update fixes related problems in compiz.
Original advisory details:
Jens Askengren discovered that gnome-screensaver became confused when
running under Compiz, and could lose keyboard lock focus. A local attacker
could exploit this to bypass the user's locked screen saver.
Instructions: After a standard system upgrade you need to restart your session to effect
the necessary changes.
Ubuntu
gnome-screensaver vulnerability
vendor_ubuntu·2007-10-23
CVE-2007-3920 gnome-screensaver vulnerability
Title: gnome-screensaver vulnerability
Summary: gnome-screensaver vulnerability
Jens Askengren discovered that gnome-screensaver became confused when
running under Compiz, and could lose keyboard lock focus. A local
attacker could exploit this to bypass the user's locked screen saver.
Instructions: After a standard system upgrade you need to restart your session to effect
the necessary changes.
Red Hat
gnome-screensaver loses keyboard grab when running under compiz
vendor_redhat·2007-10-19·CVSS 4.6
CVE-2007-3920 [MEDIUM] gnome-screensaver loses keyboard grab when running under compiz
gnome-screensaver loses keyboard grab when running under compiz
GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.
Debian
CVE-2007-3920: gnome-screensaver - GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly ...
vendor_debian·2007·CVSS 4.6
CVE-2007-3920 [MEDIUM] CVE-2007-3920: gnome-screensaver - GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly ...
GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.
Scope: local
bookworm: resolved (fixed in 2.20.0-1.1)
bullseye: resolved (fixed in 2.20.0-1.1)
trixie: resolved (fixed in 2.20.0-1.1)
GHSA
GHSA-qf9j-crg7-4p68: The Expo plugin in Compiz Fusion 0
ghsa_unreviewed·2022-05-17·CVSS 6.2
CVE-2008-6514 [MEDIUM] GHSA-qf9j-crg7-4p68: The Expo plugin in Compiz Fusion 0
The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.
GHSA
GHSA-pq79-5jg4-62p2: GNOME screensaver 2
ghsa_unreviewed·2022-05-01·CVSS 4.6
CVE-2007-3920 [MEDIUM] GHSA-pq79-5jg4-62p2: GNOME screensaver 2
GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.
OSV
CVE-2007-3920: GNOME screensaver 2
osv·2007-10-29·CVSS 4.6
CVE-2007-3920 [MEDIUM] CVE-2007-3920: GNOME screensaver 2
GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-6514 compiz-fusion: Possible locked desktop access by using Expo plugin mouse shortcuts
bugzilla·2009-03-24·CVSS 6.2
CVE-2008-6514 [MEDIUM] CVE-2008-6514 compiz-fusion: Possible locked desktop access by using Expo plugin mouse shortcuts
CVE-2008-6514 compiz-fusion: Possible locked desktop access by using Expo plugin mouse shortcuts
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-6514 to
the following vulnerability:
The Expo plugin in Compiz Fusion 0.7.8 allows local users with
physical access to drag the screen saver aside and access the locked
desktop by using Expo mouse shortcuts, a related issue to
CVE-2007-3920.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6514
https://bugs.launchpad.net/ubuntu/+source/compiz-fusion-plugins-main/+bug/247088
http://bugzilla.gnome.org/show_bug.cgi?id=561567
http://www.securityfocus.com/bid/32712
http://secunia.com/advisories/33077
http://xforce.iss.net/xforce/xfdb/47172
Upstream patch:
http://gitweb.compiz-fusion.org/?p=fusion/plugins/expo;
Bugzilla
CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz [F8]
bugzilla·2007-11-01·CVSS 6.2
CVE-2007-3920 [MEDIUM] CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz [F8]
CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz [F8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Please make an update s soon as possible!
---
Ping
---
Lubomír, what's this? Is this still alive?
---
Matej: This was adressed in [1]. Bodhi will close this soon.
[1] https://admin.fedoraproject.org/updates/F8/FEDORA-2008-0930
---
xorg-x11-server-1.3.0.0-40.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz [FC6]
bugzilla·2007-10-29·CVSS 6.2
CVE-2007-3920 [MEDIUM] CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz [FC6]
CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Please make an update as soon as possible!
---
Ping
---
FC6 reached EOL.
Bugzilla
CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz [Fdevel]
bugzilla·2007-10-29·CVSS 6.2
CVE-2007-3920 [MEDIUM] CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz [Fdevel]
CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Please make an update as soon as possible!
---
Ping
---
This is fixed in rawhide, we're shipping a pre 1.5 git snapshot which has the
fix in it.
Bugzilla
CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz [F7]
bugzilla·2007-10-29·CVSS 6.2
CVE-2007-3920 [MEDIUM] CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz [F7]
CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Please make an update as soon as possible!
---
Ping
---
xorg-x11-server-1.3.0.0-16.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz
bugzilla·2007-10-24·CVSS 6.2
CVE-2007-3920 [MEDIUM] CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz
CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz
Description of problem:
From upstream bugzilla:
If compiz is used and "Unredirected Fullscreen mode" is turned on the
gnome-screensaver keybord grab does not work. Its possible to input into
(hidden) windows then.
Additional info:
Upstream bug report contains patch. Feel free to request freeze break for f8 to
fix this, as it has security implications.
References:
https://launchpad.net/bugs/145123
http://bugzilla.gnome.org/show_bug.cgi?id=488264
Discussion:
hmm, if what the person says is true, then the patch can't be right. that means
gnome-screensaver is running without a keyboard grab in effect?!
---
ajax, is "XCompositeUnredirectWindow()" really dropping grabs?
---
It looks like it is:
for (ccw =
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.htmlhttp://secunia.com/advisories/27381http://secunia.com/advisories/28627http://secunia.com/advisories/30329http://secunia.com/advisories/30715http://www.redhat.com/support/errata/RHSA-2008-0485.htmlhttp://www.securityfocus.com/bid/26188http://www.ubuntu.com/usn/usn-537-1http://www.ubuntu.com/usn/usn-537-2https://bugzilla.redhat.com/show_bug.cgi?id=357071https://bugzilla.redhat.com/show_bug.cgi?id=363061https://exchange.xforce.ibmcloud.com/vulnerabilities/37410https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10192https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00811.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00841.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.htmlhttp://secunia.com/advisories/27381http://secunia.com/advisories/28627http://secunia.com/advisories/30329http://secunia.com/advisories/30715http://www.redhat.com/support/errata/RHSA-2008-0485.htmlhttp://www.securityfocus.com/bid/26188http://www.ubuntu.com/usn/usn-537-1http://www.ubuntu.com/usn/usn-537-2https://bugzilla.redhat.com/show_bug.cgi?id=357071https://bugzilla.redhat.com/show_bug.cgi?id=363061https://exchange.xforce.ibmcloud.com/vulnerabilities/37410https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10192https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00811.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00841.html
2007-10-29
Published