漏洞信息详情
XScreenSaver本地口令泄漏漏洞
- CNNVD编号:CNNVD-200412-552
- 危害等级: 中危
- CVE编号:
CVE-2004-2655
- 漏洞类型:
设计错误
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2010-04-02
- 厂 商:
xscreensaver - 漏洞来源:
-
漏洞简介
XScreenSaver是一套基于X Window系统的屏幕保护程序。
XScreenSaver提示用户输入口令解锁屏幕时存在键盘焦点漏洞。XScreenSaver没有正确的保证拥有正确的键盘焦点,这可能将用户口令泄漏给有键盘焦点的程序。这种行为并不常见,因为仅有一些应用程序出现这种焦点错误。
<*链接:http://marc.theaimsgroup.com/?l=bugtraq&m=114962062927164&w=2
http://secunia.com/advisories/20226/print/
http://lwn.net/Alerts/184909
*>
漏洞公告
厂商补丁:
RedHat
——
RedHat已经为此发布了一个安全公告(RHSA-2006:0498-01)以及相应补丁:
RHSA-2006:0498-01:Moderate: xscreensaver security update
链接:http://lwn.net/Alerts/184909” target=”_blank”>
http://lwn.net/Alerts/184909
补丁下载:
Red Hat Enterprise Linux AS (Advanced Server) version 2.1:
SRPMS:
ftp://updates.redhat.com/enterprise/2.1AS/en/os/SRPMS/xscreensaver-3.33-4.rhel21.3.src.rpm
f8a3f186605e8c1e94118d560724cd0c xscreensaver-3.33-4.rhel21.3.src.rpm
i386:
3f48fa1db2d0c4224dd968a3a4a10033 xscreensaver-3.33-4.rhel21.3.i386.rpm
ia64:
dfe54c3a32cc18cd4cdf4ccfe073cba0 xscreensaver-3.33-4.rhel21.3.ia64.rpm
Red Hat Linux Advanced Workstation 2.1:
SRPMS:
ftp://updates.redhat.com/enterprise/2.1AW/en/os/SRPMS/xscreensaver-3.33-4.rhel21.3.src.rpm
f8a3f186605e8c1e94118d560724cd0c xscreensaver-3.33-4.rhel21.3.src.rpm
ia64:
dfe54c3a32cc18cd4cdf4ccfe073cba0 xscreensaver-3.33-4.rhel21.3.ia64.rpm
Red Hat Enterprise Linux ES version 2.1:
SRPMS:
ftp://updates.redhat.com/enterprise/2.1ES/en/os/SRPMS/xscreensaver-3.33-4.rhel21.3.src.rpm
f8a3f186605e8c1e94118d560724cd0c xscreensaver-3.33-4.rhel21.3.src.rpm
i386:
3f48fa1db2d0c4224dd968a3a4a10033 xscreensaver-3.33-4.rhel21.3.i386.rpm
Red Hat Enterprise Linux WS version 2.1:
SRPMS:
ftp://updates.redhat.com/enterprise/2.1WS/en/os/SRPMS/xscreensaver-3.33-4.rhel21.3.src.rpm
f8a3f186605e8c1e94118d560724cd0c xscreensaver-3.33-4.rhel21.3.src.rpm
i386:
3f48fa1db2d0c4224dd968a3a4a10033 xscreensaver-3.33-4.rhel21.3.i386.rpm
Red Hat Enterprise Linux AS version 3:
SRPMS:
ftp://updates.redhat.com/enterprise/3AS/en/os/SRPMS/xscreensaver-4.10-20.src.rpm
aeb44a2230e0891747e7c678e165c2b0 xscreensaver-4.10-20.src.rpm
i386:
32064f1c5108a2fc8d440099113a915f xscreensaver-4.10-20.i386.rpm
c3c5cbe5a9f4dc689ba1cc8168dfda10 xscreensaver-debuginfo-4.10-20.i386.rpm
ia64:
ac46f647bd7930f3dcf10b74d4f8f9ec xscreensaver-4.10-20.ia64.rpm
ebf73db97fdda4f4d65e6897050ca206 xscreensaver-debuginfo-4.10-20.ia64.rpm
ppc:
6023bea1b1145194a72487f7418b9c8b xscreensaver-4.10-20.ppc.rpm
fcb479f611c9053efd9d845bcdbc7ffe xscreensaver-debuginfo-4.10-20.ppc.rpm
s390:
0e9f6a02afe107a9b52334eb89c0a0b1 xscreensaver-4.10-20.s390.rpm
26f350733c38fc054ea14b3cf8f08b77 xscreensaver-debuginfo-4.10-20.s390.rpm
s390x:
e48435174e377c0c7b78b2f87c16aab5 xscreensaver-4.10-20.s390x.rpm
7772d366de77b390edd9e3593b1d6d5b xscreensaver-debuginfo-4.10-20.s390x.rpm
x86_64:
83193c35d8ddf707af150d1e507fdc61 xscreensaver-4.10-20.x86_64.rpm
0177ce9d9a124b43310f450212ef271a xscreensaver-debuginfo-4.10-20.x86_64.rpm
Red Hat Desktop version 3:
SRPMS:
ftp://updates.redhat.com/enterprise/3desktop/en/os/SRPMS/xscreensaver-4.10-20.src.rpm
aeb44a2230e0891747e7c678e165c2b0 xscreensaver-4.10-20.src.rpm
i386:
32064f1c5108a2fc8d440099113a915f xscreensaver-4.10-20.i386.rpm
c3c5cbe5a9f4dc689ba1cc8168dfda10 xscreensaver-debuginfo-4.10-20.i386.rpm
x86_64:
83193c35d8ddf707af150d1e507fdc61 xscreensaver-4.10-20.x86_64.rpm
0177ce9d9a124b43310f450212ef271a xscreensaver-debuginfo-4.10-20.x86_64.rpm
Red Hat Enterprise Linux ES version 3:
SRPMS:
ftp://updates.redhat.com/enterprise/3ES/en/os/SRPMS/xscreensaver-4.10-20.src.rpm
aeb44a2230e0891747e7c678e165c2b0 xscreensaver-4.10-20.src.rpm
i386:
32064f1c5108a2fc8d440099113a915f xscreensaver-4.10-20.i386.rpm
c3c5cbe5a9f4dc689ba1cc8168dfda10 xscreensaver-debuginfo-4.10-20.i386.rpm
ia64:
ac46f647bd7930f3dcf10b74d4f8f9ec xscreensaver-4.10-20.ia64.rpm
ebf73db97fdda4f4d65e6897050ca206 xscreensaver-debuginfo-4.10-20.ia64.rpm
x86_64:
83193c35d8ddf707af150d1e507fdc61 xscreensaver-4.10-20.x86_64.rpm
0177ce9d9a124b43310f450212ef271a xscreensaver-debuginfo-4.10-20.x86_64.rpm
Red Hat Enterprise Linux WS version 3:
SRPMS:
ftp://updates.redhat.com/enterprise/3WS/en/os/SRPMS/xscreensaver-4.10-20.src.rpm
aeb44a2230e0891747e7c678e165c2b0 xscreensaver-4.10-20.src.rpm
i386:
32064f1c5108a2fc8d440099113a915f xscreensaver-4.10-20.i386.rpm
c3c5cbe5a9f4dc689ba1cc8168dfda10 xscreensaver-debuginfo-4.10-20.i386.rpm
ia64:
ac46f647bd7930f3dcf10b74d4f8f9ec xscreensaver-4.10-20.ia64.rpm
ebf73db97fdda4f4d65e6897050ca206 xscreensaver-debuginfo-4.10-20.ia64.rpm
x86_64:
83193c35d8ddf707af150d1e507fdc61 xscreensaver-4.10-20.x86_64.rpm
0177ce9d9a124b43310f450212ef271a xscreensaver-debuginfo-4.10-20.x86_64.rpm
可使用下列命令安装补丁:
rpm -Fvh [文件名]
Jamie Zawinski
————–
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://www.jwz.org/xscreensaver/xscreensaver-4.24.tar.gz” target=”_blank”>
http://www.jwz.org/xscreensaver/xscreensaver-4.24.tar.gz
参考网址
来源: UBUNTU
名称: USN-269-1
链接:http://www.ubuntulinux.org/support/documentation/usn/usn-269-1
来源: BID
名称: 17471
链接:http://www.securityfocus.com/bid/17471
来源: bugzilla.redhat.com
链接:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188149
来源: www.jwz.org
链接:http://www.jwz.org/xscreensaver/changelog.html
来源: www.derkeiler.com
链接:http://www.derkeiler.com/Newsgroups/comp.os.linux.security/2004-08/0018.html
来源: OVAL
名称: oval:org.mitre.oval:def:10096
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10096
来源: REDHAT
名称: RHSA-2006:0498
链接:http://www.redhat.com/support/errata/RHSA-2006-0498.html
来源: SUSE
名称: SUSE-SR:2006:023
链接:http://www.novell.com/linux/security/advisories/2006_23_sr.html
来源: MANDRIVA
名称: MDKSA-2006:071
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:071
来源: support.avaya.com
链接:http://support.avaya.com/elmodocs2/security/ASA-2006-107.htm
来源: SECTRACK
名称: 1016151
链接:http://securitytracker.com/id?1016151
来源: SECTRACK
名称: 1016150
链接:http://securitytracker.com/id?1016150
来源: SECUNIA
名称: 22080
链接:http://secunia.com/advisories/22080
来源: SECUNIA
名称: 20782
链接:http://secunia.com/advisories/20782
来源: SECUNIA
名称: 20456
链接:http://secunia.com/advisories/20456
来源: SECUNIA
名称: 20226
链接:http://secunia.com/advisories/20226
来源: SGI
名称: 20060602-01-U
链接:ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
来源:NSFOCUS
名称:8890
链接:http://www.nsfocus.net/vulndb/8890