CVE-2012-1620
published 2012-07-12CVE-2012-1620: slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive…
PriorityP48low3.6CVSS 2.0
AVLACLAuNCPIPAN
EPSS
0.51%
40.6th percentile
slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive information by pressing a button, which reveals the desktop and active windows.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | suckless-tools | < suckless-tools 39-1 (bookworm) | suckless-tools 39-1 (bookworm) |
| suckless | slock | — | — |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv3.6LOW
vendor_debian3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fwwq-76h7-8wfr: slock 0
ghsa_unreviewed·2022-05-17
CVE-2012-1620 [LOW] GHSA-fwwq-76h7-8wfr: slock 0
slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive information by pressing a button, which reveals the desktop and active windows.
OSV
CVE-2012-1620: slock 0
osv·2012-07-12·CVSS 3.6
CVE-2012-1620 [LOW] CVE-2012-1620: slock 0
slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive information by pressing a button, which reveals the desktop and active windows.
Debian
CVE-2012-1620: suckless-tools - slock 0.9 does not properly handle the XRaiseWindow event when the screen is loc...
vendor_debian·2012·CVSS 3.6
CVE-2012-1620 [LOW] CVE-2012-1620: suckless-tools - slock 0.9 does not properly handle the XRaiseWindow event when the screen is loc...
slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive information by pressing a button, which reveals the desktop and active windows.
Scope: local
bookworm: resolved (fixed in 39-1)
bullseye: resolved (fixed in 39-1)
forky: resolved (fixed in 39-1)
sid: resolved (fixed in 39-1)
trixie: resolved (fixed in 39-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1620 slock-0.9 displays modal box after locking [fedora-all]
bugzilla·2012-04-12·CVSS 3.6
CVE-2012-1620 [LOW] CVE-2012-1620 slock-0.9 displays modal box after locking [fedora-all]
CVE-2012-1620 slock-0.9 displays modal box after locking [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=
Bugzilla
CVE-2012-1620 slock-0.9 displays modal box after locking
bugzilla·2012-02-01·CVSS 3.6
CVE-2012-1620 [LOW] CVE-2012-1620 slock-0.9 displays modal box after locking
CVE-2012-1620 slock-0.9 displays modal box after locking
https://bugs.gentoo.org/show_bug.cgi?id=401645
Jeroen Roovers 2012-01-31 17:23:28 UTC
1) In a terminal, I run `slock & sleep 5; '
2) After about 10 seconds, I press some keys that slock would interpret as a
password.
3a) It does not allow me to use - all keyboard controls are
captured.
3b) Pointer device input is blocked - cannot be controlled through
the mouse.
4) Entering the correct password unlocks the screen and makes
focused and in the foreground.
The only harm I see here is a possible unwanted disclosure of the information
that happens to display at the time, but it's a vulnerability sure
enough.
Discussion:
There's also another reproducer in Comment #4.
Neither works for me with slock-0.9-9.fc16.x86_64 or slock-0.9-10r
http://hg.suckless.org/slock/rev/891a4984aba6http://secunia.com/advisories/48700http://www.openwall.com/lists/oss-security/2012/04/06/1http://www.openwall.com/lists/oss-security/2012/04/06/2http://www.osvdb.org/81035http://www.securityfocus.com/bid/52922https://bugs.gentoo.org/show_bug.cgi?id=401645https://bugzilla.redhat.com/show_bug.cgi?id=786310https://exchange.xforce.ibmcloud.com/vulnerabilities/74666http://hg.suckless.org/slock/rev/891a4984aba6http://secunia.com/advisories/48700http://www.openwall.com/lists/oss-security/2012/04/06/1http://www.openwall.com/lists/oss-security/2012/04/06/2http://www.osvdb.org/81035http://www.securityfocus.com/bid/52922https://bugs.gentoo.org/show_bug.cgi?id=401645https://bugzilla.redhat.com/show_bug.cgi?id=786310https://exchange.xforce.ibmcloud.com/vulnerabilities/74666
2012-07-12
Published