CVE-2016-10894
published 2019-08-16CVE-2016-10894: xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such…
PriorityP416medium4.6CVSS 3.1
AVPACLPRNUINSUCNIHAN
EPSS
0.36%
29.2th percentile
xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such as Chromium via events such as pan scrolling, "pinch and zoom" gestures, or even regular mouse clicks (by depressing the touchpad once and then clicking with a different finger).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xtrlock | < xtrlock 2.12 (bookworm) | xtrlock 2.12 (bookworm) |
| xtrlock | xtrlock | >= 0 < 2.12 | 2.12 |
| xtrlock | xtrlock | >= 0 < 2.12 | 2.12 |
| xtrlock | xtrlock | >= 0 < 2.12 | 2.12 |
| xtrlock | xtrlock | >= 0 < 2.12 | 2.12 |
| xtrlock_project | xtrlock | <= 2.10 | — |
CVSS provenance
nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv4.6MEDIUM
vendor_debian4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6r6w-5rm5-f9qm: xtrlock through 2
ghsa_unreviewed·2022-05-24
CVE-2016-10894 [MEDIUM] GHSA-6r6w-5rm5-f9qm: xtrlock through 2
xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such as Chromium via events such as pan scrolling, "pinch and zoom" gestures, or even regular mouse clicks (by depressing the touchpad once and then clicking with a different finger).
OSV
CVE-2016-10894: xtrlock through 2
osv·2019-08-16·CVSS 4.6
CVE-2016-10894 [MEDIUM] CVE-2016-10894: xtrlock through 2
xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such as Chromium via events such as pan scrolling, "pinch and zoom" gestures, or even regular mouse clicks (by depressing the touchpad once and then clicking with a different finger).
Debian
CVE-2016-10894: xtrlock - xtrlock through 2.10 does not block multitouch events. Consequently, an attacker...
vendor_debian·2016·CVSS 4.6
CVE-2016-10894 [MEDIUM] CVE-2016-10894: xtrlock - xtrlock through 2.10 does not block multitouch events. Consequently, an attacker...
xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such as Chromium via events such as pan scrolling, "pinch and zoom" gestures, or even regular mouse clicks (by depressing the touchpad once and then clicking with a different finger).
Scope: local
bookworm: resolved (fixed in 2.12)
bullseye: resolved (fixed in 2.12)
forky: resolved (fixed in 2.12)
sid: resolved (fixed in 2.12)
trixie: resolved (fixed in 2.12)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-08-16
Published