CVE-2015-8025

Description

driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.

Risk Information

Base Score
6.1
MODERATE
Vector
AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.058

Associated Vulnerability

VulnerabilityOS Platform
xscreensaver security update(DSA-3438-1) xscreensaver_5.15-3+deb7u1_i386.debLinux
xscreensaver security update(DSA-3438-1) xscreensaver_5.15-3+deb7u1_amd64.debLinux
SUSE-SU-2015:2053-2(SUSE Linux Enterprise Desktop 12-SP1 ) xscreensaver-5.22-7.1.x86_64.rpmLinux
SUSE-SU-2015:2053-2(SUSE Linux Enterprise Desktop 12-SP1 ) xscreensaver-data-5.22-7.1.x86_64.rpmLinux
SUSE-SU-2015:2053-2(SUSE Linux Enterprise Desktop 12-SP1 ) xscreensaver-data-debuginfo-5.22-7.1.x86_64.rpmLinux
SUSE-SU-2015:2053-2(SUSE Linux Enterprise Desktop 12-SP1 ) xscreensaver-debuginfo-5.22-7.1.x86_64.rpmLinux
SUSE-SU-2015:2053-2(SUSE Linux Enterprise Desktop 12-SP1 ) xscreensaver-debugsource-5.22-7.1.x86_64.rpmLinux
SUSE-SU-2015:2054-1(SUSE Linux Enterprise Desktop 11-SP3 ) xscreensaver-5.07-6.36.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234