CVE-2010-0732
Last modified
CVE-2010-0732 is a vulnerability of currently unknown severity. gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances and consequently allows physically proximate attackers to bypass screen locking and access an unattended workstation by pressing the Enter key many times.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances and consequently allows physically proximate attackers to bypass screen locking and access an unattended workstation by pressing the Enter key many times.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Gtk | < 2.18.5 |
| Gnome | Screensaver | < 2.28.1 |
References
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlThird Party Advisory
- http://secunia.com/advisories/39317Broken Link
- http://www.openwall.com/lists/oss-security/2010/03/05/2Mailing List, Patch
- http://www.securityfocus.com/bid/38211Third Party Advisory, VDB Entry
- https://bugs.edge.launchpad.net/ubuntu/+source/gnome-screensaver/+bug/446395Third Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=598476Issue Tracking, Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=565527Issue Tracking, Patch
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlThird Party Advisory
- http://secunia.com/advisories/39317Broken Link
- http://www.openwall.com/lists/oss-security/2010/03/05/2Mailing List, Patch
- http://www.securityfocus.com/bid/38211Third Party Advisory, VDB Entry
- https://bugs.edge.launchpad.net/ubuntu/+source/gnome-screensaver/+bug/446395Third Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=598476Issue Tracking, Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=565527Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-0732?
How severe is CVE-2010-0732?
How do I fix CVE-2010-0732?
Are you affected by CVE-2010-0732?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
