oss-sec mailing list archives
Re: CVE id request: xscreensaver
From: "Bernhard R. Link" <brlink () debian org>
Date: Sun, 25 May 2008 19:00:08 +0200
* Tomas Hoger <thoger () redhat com> [080525 16:03]:
Is there any known attack vector crossing trust boundary? Usage of xrandr should be fully under the control of the user running xscreensaver.
Some vectors might be thinkable due to increasing automation:
Perhaps some desktop environments realize a external monitor vanishing
and rearrange the layout (which is quite nice to avoid programs being
in invisible parts of the layout).
If that is the case a local attacker might use this weakness gain access
to the account without getting noticed that easily as when opening the
case of the computer.
An already possible attack vector, though needing very unlikely
requirements: An user issued an ssh -X localhost to an more priviliged
account in an xterm and started an xscreenserver there, because he
suspects someone else might know the password and login with the
unprivileged account he is logged in. Then this sense of protection
would be false due to this problem. The unlikely part is that this
would only work if the computer was not running before since the
possible compromize of the password and only connected to the net
after entering the password into ssh. So also in that case it could
only widen a gap that is hardly totally closed anyway.
Hochachtungsvoll,
Bernhard R. Link
Current thread:
- CVE id request: xscreensaver Steffen Joeris (May 25)
- Re: CVE id request: xscreensaver Tomas Hoger (May 25)
- Re: CVE id request: xscreensaver Steffen Joeris (May 25)
- Re: CVE id request: xscreensaver Nico Golde (May 25)
- Re: CVE id request: xscreensaver Bernhard R. Link (May 25)
- Re: CVE id request: xscreensaver Tomas Hoger (May 25)
