A buffer overflow in Xlockmore might allow remote attackers to cause a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201309-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Xlockmore: Denial of Service Date: September 02, 2013 Bugs: #255229, #440776, #477328 ID: 201309-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow in Xlockmore might allow remote attackers to cause a Denial of Service. Background ========= Xlockmore is just another screensaver application for X. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 x11-misc/xlockmore < 5.43 > = 5.43 Description ========== A Denial of Service flaw was found in the way Xlockmore performed the passing of arguments to the underlying localtime() call, when the 'dlock' mode was used. Impact ===== A local attacker could possibly cause a Denial of Service condition and potentially obtain unauthorized access to the graphical session, previously locked by another user. Workaround ========= There is no known workaround at this time. Resolution ========= All Xlockmore users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-misc/xlockmore-5.43" References ========= [ 1 ] CVE-2012-4524 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4524 [ 2 ] CVE-2013-4143 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4143 Availability =========== This GLSA and any updates to it are available for viewing at theGentoo Security Website: https://security.gentoo.org/glsa/201309-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
A root exploit has been found in xlockmore packaged with Slackware.. A root exploit has been found in xlockmore packaged with Slackware. By providing a carefully crafted display variable to xlock, it is possible for a local attacker to gain root access. Anyone running xlock on a public machine should upgrade to this version of xlock (or disable xlock altogether) immediately. The package described below will work for users of Slackware 7.0, 7.1, and -current. ========================================== xlockmore 4.17.2 AVAILABLE - (x1/xlock.tgz) ========================================== A root exploit has been fixed in this release of xlockmore. The new xlock.tgz package is available from: For verification purposes, we provide the following checksums: 16-bit "sum" checksum: 53857 762 x1/xlock.tgz 128-bit MD5 message digest: ca171919342cd7a3e18a3ac3cd91e252 x1/xlock.tgz INSTALLATION INSTRUCTIONS FOR THE xlock.tgz PACKAGE: --------------------------------------------------- Disable any running xlockmore processes and issue this command: # upgradepkg xlock.tgz Remember, it's also a good idea to backup configuration files before upgrading packages. - Slackware Linux Security Team The Slackware Linux Project . A critical flaw has been discovered in xlockmore bundled with Slackware. Users are urged to update immediately or disable the application.. root Access,xlockmore,slackware,critical Update,software Importance. . Severity: Critical. LinuxSecurity.com Team
There is a format string bug in all versions of xlockmore/xlockmore-gl.. -----BEGIN PGP SIGNED MESSAGE----- - ------------------------------------------------------------------------ Debian Security Advisory
Get the latest Linux and open source security news straight to your inbox.