|Main Archive Page > Month Archives > full-disclosure-uk archives|
rPath Security Advisory: 2007-0088-1
Products: rPath Linux 1
Exposure Level Classification:
Local User Deterministic Weakness
Previous versions of xscreensaver are vulnerable to an attack that requires that the attacker have physical access. If the system is configured to use remote directory service for login credentials, an attacker who can cause or take advantage of a network failure can cause the xscreensaver process to crash, unlocking the screen, and allowing the attacker unrestricted access to the system as the logged-in user.