"Ubuntu Security Notice USN-898-1 February 10, 2010
gnome-screensaver vulnerability
CVE-2010-0414
==========================
==========================
=========
A security issue affects the following Ubuntu releases:
Ubuntu 9.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 9.10:
gnome-screensaver 2.28.0-0ubuntu3.4
After a standard system upgrade you need to restart your session to effect
the necessary changes.
Details follow:
It was discovered that gnome-screensaver did not correctly handle monitor
hotplugging. An attacker with physical access could cause gnome-screensaver
to crash and gain access to the locked session.
Updated packages for Ubuntu 9.10:
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.28.0-0ubuntu3.4.diff.gz
Size/MD5: 14438 df2eeb9fde262814316d3d909bcc29aa
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.28.0-0ubuntu3.4.dsc
Size/MD5: 1757 6aa4026ae6faa87f58a76d0def8220cb
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.28.0.orig.tar.gz
Size/MD5: 5069053 cdf328a0443a3cc30b4b2b36d9a99236
amd64 architecture (Athlon64, Opteron, EM64T Xeon):
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.28.0-0ubuntu3.4_amd64.deb
Size/MD5: 4185932 a64b30c3d21a6914d1a2376c9b85c34d
i386 architecture (x86 compatible Intel/AMD):
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.28.0-0ubuntu3.4_i386.deb
Size/MD5: 4169482 988fb3a93243e21d863462a7ec9c4d71
lpia architecture (Low Power Intel Architecture):
http://ports.ubuntu.com/pool/main/g/gnome-screensaver/gnome-screensaver=
_2.28.0-0ubuntu3.4_lpia.deb
Size/MD5: 4170332 40dcb1fb1c203811b2c4c0895a9e22af
powerpc architecture (Apple Macintosh G3/G4/G5):
http://ports.ubuntu.com/pool/main/g/gnome-screensaver/gnome-screensaver=
_2.28.0-0ubuntu3.4_powerpc.deb
Size/MD5: 4179928 709de0a74df0c05f3605b30eae34edba
sparc architecture (Sun SPARC/UltraSPARC):
http://ports.ubuntu.com/pool/main/g/gnome-screensaver/gnome-screensaver=
_2.28.0-0ubuntu3.4_sparc.deb
Size/MD5: 4178372 cc91e447b311c1f509cbcfbf635c92a6
--=-UVW1wAISkaADGphJLKuu
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEABECAAYFAkty0tQACgkQLMAs/0C4zNpsiwCfdesxv8k2YpxqX82Ggu1FVWTB
suIAnAqGGeStxQnvwwGY3uTk+8EKKUNo
=xKzG
-----END PGP SIGNATURE-----
"
USN-883-1: network-manager-applet vulnerabilitiesVictoria fumes as David Beckham has his balls grabbed
This entry was posted
on 4:23 PM
.
Archives
-
▼
2010
(391)
-
▼
February
(42)
- USN-905-1: sudo vulnerabilities
- RHSA-2010:0115-01 Moderate: pidgin security update
- RHSA-2010:0122-01 Important: sudo security update
- USN-904-1: Squid vulnerability
- DSA 2003-1: New Linux 2.6.18 packages fix several ...
- DSA-2002-1: New polipo packages fix denial of service
- RHSA-2010:0114-01 Critical: acroread security and ...
- USN-902-1: Pidgin vulnerabilities
- DSA 1999-1: New xulrunner packages fix several vul...
- USN-895-1: Firefox 3.0 and Xulrunner 1.9 vulnerabi...
- USN-890-5: XML-RPC for C and C++ vulnerabilities
- DSA 2000-1: New ffmpeg packages fix several vulner...
- RHSA-2010:0110-01 Moderate: mysql security update
- RHSA-2010:0115-01 Moderate: pidgin security update
- USN-896-1: Firefox 3.5 and Xulrunner 1.9.1 vulnera...
- RHSA-2010:0112-01 Critical: firefox security update
- RHSA-2010:0113-01 Critical: seamonkey security update
- DSA 1998-1: New kdelibs packages fix arbitrary cod...
- RHSA-2010:0108-01 Moderate: NetworkManager securit...
- USN-900-1: Ruby vulnerabilities
- USN-898-1: gnome-screensaver vulnerability
- RHSA-2010:0103-01 Important: flash-plugin security...
- DSA-1997-1: New mysql-dfsg-5.0 packages fix severa...
- DSA 1994-1: New ajaxterm packages fix session hija...
- RHSA-2010:0102-01 Important: flash-plugin security...
- USN-897-1: MySQL vulnerabilities
- USN-899-1: Tomcat vulnerabilities
- DSA 1992-1: New chrony packages fix denial of service
- DSA 1993-1: New otrs2 packages fix SQL injection
- RHSA-2010:0094-02 Critical: HelixPlayer security u...
- RHSA-2010:0079-01 Important: kernel security and b...
- DSA 1986-1: New moodle packages fix several vulner...
- DSA 1991-1: New squid/squid3 packages fix denial o...
- RHSA-2010:0088-02 Important: kvm security and bug ...
- DSA-1989-1: New fuse packages fix denial of service
- DSA 1841-2: New git-core packages fix build failure
- DSA 1987-1: New lighttpd packages fix denial of se...
- DSA 1983-1: New Wireshark packages fix several vul...
- DSA-1990-2: New trac-git package fixes regression
- DSA-1990-1: New trac-git packages fix code execution
- DSA 1982-1: New hybserv packages fix denial of ser...
- DSA 1968-2: New pdns-recursor packages fix cache p...
-
▼
February
(42)