Submitted by KeesCook on Tue, 2007-06-12 23:33
Referenced CVEs:
CVE-2007-1859
Description:
===========================================================
Ubuntu Security Notice USN-474-1 June 12, 2007
xscreensaver vulnerability
CVE-2007-1859
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
xscreensaver 4.23-4ubuntu8.1
Ubuntu 6.10:
xscreensaver 4.24-4ubuntu2.1
Ubuntu 7.04:
xscreensaver 4.24-5ubuntu2.1
After a standard system upgrade you need to restart your session to
effect the necessary changes.
Details follow:
It was discovered that xscreensaver did not correctly validate the
return values from network authentication systems such as LDAP or NIS.
A local attacker could bypass a locked screen if they were able to
interrupt network connectivity.


