Severity
6.9MEDIUMNVD
EPSS
0.0%
top 88.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 3
Latest updateMay 2

Description

Race condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock module in kdebase in KDE SC 4.4.0 allows physically proximate attackers to bypass KScreenSaver screen locking and access an unattended workstation by pressing the Enter key at a certain time, related to multiple forked processes.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages1 packages

NVDkde/kde_sc4.4.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8jgf-9www-j7x4: Race condition in workspace/krunner/lock/lockdlg2022-05-02
CVEList
CVE-2010-0923: Race condition in workspace/krunner/lock/lockdlg2010-03-03

📋Vendor Advisories

1
Red Hat
kdebase: race condition may allow local attackers to bypass screen locking2010-02-12

💬Community

1
Bugzilla
CVE-2010-0923 kdebase: race condition may allow local attackers to bypass screen locking2010-03-03
CVE-2010-0923 — Race Condition in KDE SC | cvebase