CVE-2021-34557Classic Buffer Overflow in Xscreensaver

Severity
4.6MEDIUMNVD
EPSS
0.1%
top 79.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10
Latest updateMay 24

Description

XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in update_screen_layout() allows an attacker to bypass the standard screen lock authentication mechanism by crashing XScreenSaver. The attacker must physically disconnect many video outputs.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 0.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/xscreensaver< xscreensaver 5.45+dfsg1-2 (bookworm)
Debianxscreensaver/xscreensaver< 5.45+dfsg1-2+3

Also affects: Fedora 33

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hrwv-325w-f6ch: XScreenSaver 52022-05-24
OSV
CVE-2021-34557: XScreenSaver 52021-06-10

📋Vendor Advisories

1
Debian
CVE-2021-34557: xscreensaver - XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectabl...2021
CVE-2021-34557 — Classic Buffer Overflow | cvebase