- Description
- The default configuration in gnome-screensaver 3.5.4 through 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prevents the program from starting automatically after login and allows physically proximate attackers to bypass screen locking and access an unattended workstation.
- Source
- security@ubuntu.com
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
- nvd@nist.gov
- CWE-264
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gnome:gnome_screensaver:3.5.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "48224CBC-49B5-49CE-8665-3FFC2359778C"
},
{
"criteria": "cpe:2.3:a:gnome:gnome_screensaver:3.5.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "688B61C0-4213-43DE-862C-55A057118173"
},
{
"criteria": "cpe:2.3:a:gnome:gnome_screensaver:3.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9EA343E-C571-4253-97FC-2E2B17537BD4"
}
],
"operator": "OR"
}
]
}
]