CVE-2004-2655

rdesktop 1.3.1 with xscreensaver 4.14, and possibly other versions, when running on Fedora and possibly other platforms, does not release the keyboard focus when xscreensaver starts, which causes the password to be entered into the active window when the user unlocks the screen.
References
Link Resource
ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
http://secunia.com/advisories/20226
http://secunia.com/advisories/20456
http://secunia.com/advisories/20782
http://secunia.com/advisories/22080
http://securitytracker.com/id?1016150
http://securitytracker.com/id?1016151
http://support.avaya.com/elmodocs2/security/ASA-2006-107.htm
http://www.derkeiler.com/Newsgroups/comp.os.linux.security/2004-08/0018.html
http://www.jwz.org/xscreensaver/changelog.html
http://www.mandriva.com/security/advisories?name=MDKSA-2006:071
http://www.novell.com/linux/security/advisories/2006_23_sr.html
http://www.redhat.com/support/errata/RHSA-2006-0498.html
http://www.securityfocus.com/bid/17471 Patch
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188149
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10096
https://usn.ubuntu.com/269-1/
ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
http://secunia.com/advisories/20226
http://secunia.com/advisories/20456
http://secunia.com/advisories/20782
http://secunia.com/advisories/22080
http://securitytracker.com/id?1016150
http://securitytracker.com/id?1016151
http://support.avaya.com/elmodocs2/security/ASA-2006-107.htm
http://www.derkeiler.com/Newsgroups/comp.os.linux.security/2004-08/0018.html
http://www.jwz.org/xscreensaver/changelog.html
http://www.mandriva.com/security/advisories?name=MDKSA-2006:071
http://www.novell.com/linux/security/advisories/2006_23_sr.html
http://www.redhat.com/support/errata/RHSA-2006-0498.html
http://www.securityfocus.com/bid/17471 Patch
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188149
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10096
https://usn.ubuntu.com/269-1/
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xscreensaver:xscreensaver:4.14:*:*:*:*:*:*:*
cpe:2.3:a:xscreensaver:xscreensaver:4.16:*:*:*:*:*:*:*
cpe:2.3:a:xscreensaver:xscreensaver:4.17:*:*:*:*:*:*:*

History

20 Nov 2024, 23:53

Type Values Removed Values Added
References () ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc - () ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc -
References () http://secunia.com/advisories/20226 - () http://secunia.com/advisories/20226 -
References () http://secunia.com/advisories/20456 - () http://secunia.com/advisories/20456 -
References () http://secunia.com/advisories/20782 - () http://secunia.com/advisories/20782 -
References () http://secunia.com/advisories/22080 - () http://secunia.com/advisories/22080 -
References () http://securitytracker.com/id?1016150 - () http://securitytracker.com/id?1016150 -
References () http://securitytracker.com/id?1016151 - () http://securitytracker.com/id?1016151 -
References () http://support.avaya.com/elmodocs2/security/ASA-2006-107.htm - () http://support.avaya.com/elmodocs2/security/ASA-2006-107.htm -
References () http://www.derkeiler.com/Newsgroups/comp.os.linux.security/2004-08/0018.html - () http://www.derkeiler.com/Newsgroups/comp.os.linux.security/2004-08/0018.html -
References () http://www.jwz.org/xscreensaver/changelog.html - () http://www.jwz.org/xscreensaver/changelog.html -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2006:071 - () http://www.mandriva.com/security/advisories?name=MDKSA-2006:071 -
References () http://www.novell.com/linux/security/advisories/2006_23_sr.html - () http://www.novell.com/linux/security/advisories/2006_23_sr.html -
References () http://www.redhat.com/support/errata/RHSA-2006-0498.html - () http://www.redhat.com/support/errata/RHSA-2006-0498.html -
References () http://www.securityfocus.com/bid/17471 - Patch () http://www.securityfocus.com/bid/17471 - Patch
References () https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188149 - () https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188149 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10096 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10096 -
References () https://usn.ubuntu.com/269-1/ - () https://usn.ubuntu.com/269-1/ -

Information

Published : 2004-12-31 05:00

Updated : 2024-11-20 23:53


NVD link : CVE-2004-2655

Mitre link : CVE-2004-2655

CVE.ORG link : CVE-2004-2655


JSON object : View

Products Affected

xscreensaver

  • xscreensaver