CVE-2015-8025
published 2015-11-10CVE-2015-8025: driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass…
PriorityP411low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.51%
40.0th percentile
driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | xscreensaver | < xscreensaver 5.34-1 (bookworm) | xscreensaver 5.34-1 (bookworm) |
| xscreensaver | xscreensaver | >= 0 < 5.34-1 | 5.34-1 |
| xscreensaver | xscreensaver | >= 0 < 5.34-1 | 5.34-1 |
| xscreensaver | xscreensaver | >= 0 < 5.34-1 | 5.34-1 |
| xscreensaver | xscreensaver | >= 0 < 5.34-1 | 5.34-1 |
| xscreensaver_project | xscreensaver | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gfx7-7vxh-f4g8: driver/subprocs
ghsa_unreviewed·2022-05-17
CVE-2015-8025 [LOW] GHSA-gfx7-7vxh-f4g8: driver/subprocs
driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.
OSV
CVE-2015-8025: driver/subprocs
osv·2015-11-10·CVSS 2.1
CVE-2015-8025 [LOW] CVE-2015-8025: driver/subprocs
driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.
Ubuntu
XScreenSaver vulnerability
vendor_ubuntu·2015-11-03
CVE-2015-8025 XScreenSaver vulnerability
Title: XScreenSaver vulnerability
Summary: The system could be made to expose sensitive information.
It was discovered that XScreenSaver incorrectly handled unplugging an
external monitor. An attacker with physical access could use this flaw to
gain access to a locked session.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Debian
CVE-2015-8025: xscreensaver - driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an inter...
vendor_debian·2015·CVSS 2.1
CVE-2015-8025 [LOW] CVE-2015-8025: xscreensaver - driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an inter...
driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.
Scope: local
bookworm: resolved (fixed in 5.34-1)
bullseye: resolved (fixed in 5.34-1)
forky: resolved (fixed in 5.34-1)
sid: resolved (fixed in 5.34-1)
trixie: resolved (fixed in 5.34-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8025 xscreensaver: crash when unpluging second monitor cable while asking for password [epel-6]
bugzilla·2015-10-30·CVSS 2.1
CVE-2015-8025 [LOW] CVE-2015-8025 xscreensaver: crash when unpluging second monitor cable while asking for password [epel-6]
CVE-2015-8025 xscreensaver: crash when unpluging second monitor cable while asking for password [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking bug for
Bugzilla
CVE-2015-8025 xscreensaver: crash when unpluging second monitor cable while asking for password
bugzilla·2015-10-30·CVSS 2.1
CVE-2015-8025 [LOW] CVE-2015-8025 xscreensaver: crash when unpluging second monitor cable while asking for password
CVE-2015-8025 xscreensaver: crash when unpluging second monitor cable while asking for password
It was found that in in HDMI multi-screen setups, xscreensaver crashes (segfault) when the external screen is unplugged.
Original report: bug 1274452
CVE assignment:
http://seclists.org/oss-sec/2015/q4/193
Discussion:
Fedora tracking bug: bug 1274452
---
Created xscreensaver tracking bugs for this issue:
Affects: epel-6 [bug 1276594]
---
*** Bug 1276355 has been marked as a duplicate of this bug. ***
Bugzilla
xscreensaver: Unplugging HDMI cable can cause lock bypass
bugzilla·2015-10-29·CVSS 2.1
[LOW] xscreensaver: Unplugging HDMI cable can cause lock bypass
xscreensaver: Unplugging HDMI cable can cause lock bypass
In HDMI multi-screen setup, xscreensaver aborts when the external screen is plugged out, causing the unlocking of desktop on XFCE when asking for password.
Patch:
http://pkgs.fedoraproject.org/cgit/xscreensaver.git/diff/xscreensaver-5.33-0002-Modify-sigchld_hander-in_signal_hander_p-mechanism.patch?id=b57f59f3482fedf70ce7a3541094e2512290139f
CVE request (including steps to reproduce):
http://www.openwall.com/lists/oss-security/2015/10/24/2
Discussion:
Created xscreensaver tracking bugs for this issue:
Affects: fedora-all [bug 1276357]
Affects: epel-6 [bug 1276359]
---
The original bug is bug 1274452 .
---
http://www.openwall.com/lists/oss-security/2015/10/29/12
CVE-2015-8025 is now assigned.
---
Merging...
*** This bu
Bugzilla
Xscreensaver lock bypass
bugzilla·2015-10-22
[CRITICAL] Xscreensaver lock bypass
Xscreensaver lock bypass
Description of problem:
In HDMI multi-screen setups, xscreensaver crashes (segfault) when the external screen is plug out.
Then, the screen is unlocked.
How reproducible:
Steps to Reproduce:
1. Enable a dual screen configuration with an HDMI external screen
2. Lock the desktop (XFCE in my case)
3. Unplug the HDMI cable
Actual results:
The desktop is now unlocked
Expected results:
The change should be handled and in any case the desktop shall remain locked.
Additional info:
Video and discussion: https://twitter.com/Thaolia/status/656823859304398848
Discussion:
I cannot reproduce this issue.
* Would you result the result of
$ rpm -qa | sort
?
* Would you attach the result of
$ xrandr
before and after you unplug the HDMI cable?
* Would you attach
/var
http://lists.opensuse.org/opensuse-updates/2015-11/msg00102.htmlhttp://www.debian.org/security/2016/dsa-3438http://www.openwall.com/lists/oss-security/2015/10/24/2http://www.openwall.com/lists/oss-security/2015/10/25/1http://www.openwall.com/lists/oss-security/2015/10/29/12http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securitytracker.com/id/1034052http://www.ubuntu.com/usn/USN-2789-1https://twitter.com/Thaolia/status/656823859304398848https://www.jwz.org/blog/2015/10/xscreensaver-5-34/http://lists.opensuse.org/opensuse-updates/2015-11/msg00102.htmlhttp://www.debian.org/security/2016/dsa-3438http://www.openwall.com/lists/oss-security/2015/10/24/2http://www.openwall.com/lists/oss-security/2015/10/25/1http://www.openwall.com/lists/oss-security/2015/10/29/12http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securitytracker.com/id/1034052http://www.ubuntu.com/usn/USN-2789-1https://twitter.com/Thaolia/status/656823859304398848https://www.jwz.org/blog/2015/10/xscreensaver-5-34/
2015-11-10
Published