CVE-2015-8025Xscreensaver vulnerability

CWE-2649 documents6 sources
Severity
2.1LOWNVD
EPSS
0.1%
top 82.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateMay 17

Description

driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages3 packages

debiandebian/xscreensaver< xscreensaver 5.34-1 (bookworm)
Debianxscreensaver/xscreensaver< 5.34-1+3

Also affects: Ubuntu Linux 12.04

🔴Vulnerability Details

2
GHSA
GHSA-gfx7-7vxh-f4g8: driver/subprocs2022-05-17
OSV
CVE-2015-8025: driver/subprocs2015-11-10

📋Vendor Advisories

2
Ubuntu
XScreenSaver vulnerability2015-11-03
Debian
CVE-2015-8025: xscreensaver - driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an inter...2015

💬Community

4
Bugzilla
CVE-2015-8025 xscreensaver: crash when unpluging second monitor cable while asking for password [epel-6]2015-10-30
Bugzilla
CVE-2015-8025 xscreensaver: crash when unpluging second monitor cable while asking for password2015-10-30
Bugzilla
xscreensaver: Unplugging HDMI cable can cause lock bypass2015-10-29
Bugzilla
Xscreensaver lock bypass2015-10-22
CVE-2015-8025 — Debian Xscreensaver vulnerability | cvebase