CVE-2011-2187
published 2019-11-27CVE-2011-2187: xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.48%
38.4th percentile
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xscreensaver | < xscreensaver 5.14-1 (bookworm) | xscreensaver 5.14-1 (bookworm) |
| xscreensaver | xscreensaver | — | — |
| xscreensaver | xscreensaver | >= 0 < 5.14-1 | 5.14-1 |
| xscreensaver | xscreensaver | >= 0 < 5.14-1 | 5.14-1 |
| xscreensaver | xscreensaver | >= 0 < 5.14-1 | 5.14-1 |
| xscreensaver | xscreensaver | >= 0 < 5.14-1 | 5.14-1 |
| xscreensaver_project | xscreensaver | < 5.14 | 5.14 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xscreensaver: exits when activated (DPMSForceLevel)
vendor_redhat·2011-05-10·CVSS 7.8
CVE-2011-2187 [HIGH] xscreensaver: exits when activated (DPMSForceLevel)
xscreensaver: exits when activated (DPMSForceLevel)
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
Statement: Not vulnerable. This issue did not affect the versions of xscreensaver as
shipped with Red Hat Enterprise Linux 4.
Package: xscreensaver (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2011-2187: xscreensaver - xscreensaver before 5.14 crashes during activation and leaves the screen unlocke...
vendor_debian·2011·CVSS 7.8
CVE-2011-2187 [HIGH] CVE-2011-2187: xscreensaver - xscreensaver before 5.14 crashes during activation and leaves the screen unlocke...
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
Scope: local
bookworm: resolved (fixed in 5.14-1)
bullseye: resolved (fixed in 5.14-1)
forky: resolved (fixed in 5.14-1)
sid: resolved (fixed in 5.14-1)
trixie: resolved (fixed in 5.14-1)
GHSA
GHSA-p786-96f8-68ff: xscreensaver before 5
ghsa_unreviewed·2022-04-22
CVE-2011-2187 [HIGH] CWE-306 GHSA-p786-96f8-68ff: xscreensaver before 5
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
OSV
CVE-2011-2187: xscreensaver before 5
osv·2019-11-27·CVSS 7.8
CVE-2011-2187 [HIGH] CVE-2011-2187: xscreensaver before 5
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/cve-2011-2187https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627382https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2187https://security-tracker.debian.org/tracker/CVE-2011-2187https://www.jwz.org/xscreensaver/changelog.htmlhttps://www.openwall.com/lists/oss-security/2011/06/06/17https://access.redhat.com/security/cve/cve-2011-2187https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627382https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2187https://security-tracker.debian.org/tracker/CVE-2011-2187https://www.jwz.org/xscreensaver/changelog.htmlhttps://www.openwall.com/lists/oss-security/2011/06/06/17
2019-11-27
Published