XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.
                
            References
                    Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
History
                    No history.
Information
                Published : 2007-05-02 20:19
Updated : 2017-10-11 01:32
NVD link : CVE-2007-1859
Mitre link : CVE-2007-1859
CVE.ORG link : CVE-2007-1859
JSON object : View
Products Affected
                redhat
- linux_advanced_workstation
 - enterprise_linux
 - enterprise_linux_desktop
 
xscreensaver
- xscreensaver
 
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
