CVE-2013-1050

The default configuration in gnome-screensaver 3.5.4 through 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prevents the program from starting automatically after login and allows physically proximate attackers to bypass screen locking and access an unattended workstation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:gnome_screensaver:3.5.4:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gnome_screensaver:3.5.5:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gnome_screensaver:3.6.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:48

Type Values Removed Values Added
References () http://www.ubuntu.com/usn/USN-1716-1 - () http://www.ubuntu.com/usn/USN-1716-1 -
References () https://bugs.launchpad.net/ubuntu/+source/gnome-screensaver/+bug/1120126 - Vendor Advisory () https://bugs.launchpad.net/ubuntu/+source/gnome-screensaver/+bug/1120126 - Vendor Advisory
References () https://bugzilla.gnome.org/show_bug.cgi?id=683060 - () https://bugzilla.gnome.org/show_bug.cgi?id=683060 -
References () https://git.gnome.org/browse/gnome-screensaver/commit/?id=1940dc6bc8ad5ee2c029714efb1276c05ca80bd4 - () https://git.gnome.org/browse/gnome-screensaver/commit/?id=1940dc6bc8ad5ee2c029714efb1276c05ca80bd4 -

Information

Published : 2013-03-08 22:55

Updated : 2024-11-21 01:48


NVD link : CVE-2013-1050

Mitre link : CVE-2013-1050

CVE.ORG link : CVE-2013-1050


JSON object : View

Products Affected

gnome

  • gnome_screensaver
CWE
CWE-264

Permissions, Privileges, and Access Controls