CVE-2013-1050
The default configuration in gnome-screensaver 3.5.4 through 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prevents the program from starting automatically after login and allows physically proximate attackers to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The default configuration in gnome-screensaver 3.5.4 through 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prevents the program from starting automatically after login and allows physically proximate attackers to bypass screen locking and access an unattended workstation.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- gnome/gnome screensaver
- Source
- security@ubuntu.com
References
- http://www.ubuntu.com/usn/USN-1716-1
- https://bugs.launchpad.net/ubuntu/+source/gnome-screensaver/+bug/1120126Vendor Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=683060
- https://git.gnome.org/browse/gnome-screensaver/commit/?id=1940dc6bc8ad5ee2c029714efb1276c05ca80bd4
- http://www.ubuntu.com/usn/USN-1716-1
- https://bugs.launchpad.net/ubuntu/+source/gnome-screensaver/+bug/1120126Vendor Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=683060
- https://git.gnome.org/browse/gnome-screensaver/commit/?id=1940dc6bc8ad5ee2c029714efb1276c05ca80bd4
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.