You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa xscreensaver

Sigurnosni nedostatak programskog paketa xscreensaver

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-2789-1
November 03, 2015

xscreensaver vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 12.04 LTS

Summary:

The system could be made to expose sensitive information.

Software Description:
– xscreensaver: Automatic screensaver for X

Details:

It was discovered that XScreenSaver incorrectly handled unplugging an
external monitor. An attacker with physical access could use this flaw to
gain access to a locked session.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
xscreensaver 5.15-2ubuntu1.1

After a standard system update you need to restart your session to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2789-1
CVE-2015-8025

Package Information:
https://launchpad.net/ubuntu/+source/xscreensaver/5.15-2ubuntu1.1

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJWOUA6AAoJEGVp2FWnRL6TwmoP/iuI5kNBZ8mVqOixR0BQ3Lp8
k7P678fHJnUKiLoDFxq3YjppD6vViSWmlpuyH/b9U4Dvl5NNgIVukgtDZXWRlRWH
ALwQ2NBgL2N2LN6jafpfiS0ank8hdTg+dcvTy1wUa2OfoRQJZDNrFdxTPOAS5zp1
4lxAIY04306yLvECBrD7FbY+fvHEDB+UHFwAvnNQs5zMQL73iMM+WtqhNdsC15zV
QOwjoRwvQJEENTAy20cUh92Kgr835JPgd3aVYvL609oy2fKY1kg1zVm+eWfWe7k+
/ydbGEx0IbqL0opuGgZQCtvvWtOaonfodaK+wDr9msChihUNDrKbRr69q4CdwZoj
oQbWH3G2u3tz7CLIvWiTFa/7vKarT1gwKWx/ZFk8rnzqbJWH0MPKNiBLqCCclYt6
EhOlv9yxT83Qf/wnVS40vMNuhTju4CGs6xF8aE8bWBZ9KO7jdU/uWkA0BLOl5xwG
+cK4wstHgLgf0ANac9AP0cfvcP3HxdrNGndfjicWCrNiYpzovw2j4SMYUJ+hKQex
kCmHsGk6aaZbKilZQH0UFLQfUbhjvf6JM5fyUEh2annqWxJXXG+6oh20fohtqepk
Lqhcq/VcMvNrOsKddCQO7392KqGOuIu8sTXT/wtBRowAcTYLLOSnfLo9fyF0oGJ3
9hldzJuSP1RtQ251T0mz
=4H3h
—–END PGP SIGNATURE—–

AutorMarijo Plepelic
Cert idNCERT-REF-2015-11-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa MirBSD Korn Shell

Otkriven je sigurnosni nedostatak u programskom paketu MirBSD Korn Shell. Otkriveni nedostatak potencijalnim napadačima omogućuje dodavanje vrijednosti parametrima za razne...

Close