Home
Home
    • Blog
    • Clinic
    • Contact
    • Download
    • Video
    • Login

Poll

Favourite console text editor in Ubuntu:

LXer -- Linux and Open Source News

  • How to correctly create ODF documents using zip
  • Ubuntu Server: The Linux OS Dark Horse
  • 7 of the Best Free Linux Medical Imaging Software
  • Digg Moves From MySQL to NoSQL
  • This week at LWN: SCALE 8x: Color management for everyone
more

Linux Today

  • A System Monitoring Tool Primer
  • Linux coolness: Linux Cooler, Linux serves you beer
  • OSI Board Addition May Bring Needed Change
  • Top 10 IT Billionaires -- A Closer Look
  • Proof Of Concept: Open-Source Multi-GPU Rendering!
more

Linux Insider

  • Android Has Enough Class for Opera
  • Ubuntu Dumps the Brown
more

USN-669-1: gnome-screensaver vulnerabilities

Submitted by k4tz on Wed, 11/12/2008 - 11:40
  • Edubuntu
  • Gnome
  • Kubuntu
  • Linux World
  • Security
  • Ubuntu
  • Xubuntu

===========================================================

Ubuntu Security Notice USN-669-1 November 11, 2008

gnome-screensaver vulnerabilities CVE-2007-6389, CVE-2008-0887 ===========================================================

A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: gnome-screensaver 2.14.3-0ubuntu1.1 Ubuntu 7.10: gnome-screensaver 2.20.0-0ubuntu4.3 After a standard system upgrade you need to restart all user sessions on your computer to effect the necessary changes.

Details follow: It was discovered that the notify feature in gnome-screensaver could let a local attacker read the clipboard contents of a locked session by using Ctrl-V. (CVE-2007-6389) Alan Matsuoka discovered that gnome-screensaver did not properly handle network outages when using a remote authentication service. During a network interruption, or by disconnecting the network cable, a local attacker could gain access to locked sessions. (CVE-2008-0887)

 

Source: http://www.ubuntu.com/usn/USN-669-1

  • Add new comment

Recent blog posts

  • Configure ThinkPad laptop trackpoint on Ubuntu
  • How to make WPA connection in Ubuntu on demand
  • Review: Sabily 9.10 - Linux Ubuntu for Muslims
  • How to Install 64bit flash on Ubuntu
  • How to get Wireless LAN (Broadcom) on Acer Aspire 4720Z working with Ubuntu 9.10
  • Quick loot at Ubuntu 10.04 Lucid Lynx Alpha 3
  • System testing and benchmarking under Ubuntu 9.10
  • How to PXE booting Ubuntu Installer
  • How to Install Debian onto your Nexus One using Ubuntu
  • (Re) Install a Linux Kernel
more

Linux World

  • Microsoft's Internet Driving Licence: stupid, unworkable and unenforceable
  • Making a videoloop with Kino and Audacity
  • So is ChromeOS a desktop winner? I think not
  • Firefogg: Transcoding videos to open web standards with Mozilla Firefox
  • The Morevna Project: Anime with Synfig and Blender
Archive Syndicate content

Recent comments

  • Re
    9 weeks 5 days ago
  • Re
    9 weeks 6 days ago
  • Re
    10 weeks 5 days ago
  • Re
    11 weeks 2 days ago
  • Re
    11 weeks 6 days ago
  • Re
    12 weeks 2 hours ago
  • Re
    12 weeks 1 day ago
  • iwl3945
    13 weeks 5 days ago
  • HomeBank
    25 weeks 6 days ago
  • KMyMoney and direct connect to banks
    30 weeks 1 day ago
All contents copyright © 2008, Dhuha Net. All rights reserved
Ubuntudoctor® is a member of the Dhuha Network. Privacy Policy
RoopleTheme