VulnerabilityModified
CVE-2011-2187
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
HIGH 7.8EPSS 0.48%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.48%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- xscreensaver project/xscreensaver · debian/debian linux
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/cve-2011-2187Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627382Exploit, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2187Exploit, Issue Tracking, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-2187Third Party Advisory
- https://www.jwz.org/xscreensaver/changelog.htmlRelease Notes, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2011/06/06/17Mailing List, Third Party Advisory
- https://access.redhat.com/security/cve/cve-2011-2187Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627382Exploit, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2187Exploit, Issue Tracking, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-2187Third Party Advisory
- https://www.jwz.org/xscreensaver/changelog.htmlRelease Notes, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2011/06/06/17Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.