VulnerabilityModified
CVE-2012-3452
gnome-screensaver 3.4.x before 3.4.4 and 3.5.x before 3.5.4, when multiple screens are used, only locks the screen with the active focus, which allows physically proximate attackers to bypass screen locking and access an unattended workstation.
LOW 3.3EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
gnome-screensaver 3.4.x before 3.4.4 and 3.5.x before 3.5.4, when multiple screens are used, only locks the screen with the active focus, which allows physically proximate attackers to bypass screen locking and access an unattended workstation.
- CVSS 2.0
- 3.3 LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- gnome/screensaver
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2012/08/03/3
- http://www.openwall.com/lists/oss-security/2012/08/03/5
- https://bugzilla.gnome.org/show_bug.cgi?id=679441
- http://www.openwall.com/lists/oss-security/2012/08/03/3
- http://www.openwall.com/lists/oss-security/2012/08/03/5
- https://bugzilla.gnome.org/show_bug.cgi?id=679441
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.