MGAA-2025-0088 - Updated xscreensaver packages fix bug. MGAA-2025-0088 - Updated xscreensaver packages fix bug Publication date: 06 Nov 2025 URL: https://advisories.mageia.org/MGAA-2025-0088.html Type: bugfix Affected Mageia releases: 9 Description: The updated packages provide the latest version of xscreensaver to get rid of "This version is very old" and fix a heap buffer overflow. References: - https://bugs.mageia.org/show_bug.cgi?id=34707 SRPMS: - 9/core/xscreensaver-6.12-1.1.mga9 - 9/tainted/xscreensaver-6.12-1.1.mga9.tainted . Updated xscreensaver packages address a heap buffer overflow issue in Mageia 9, enhancing security and performance.. Mageia xscreensaver bugfix heap buffer overflow update. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for xscreensaver ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2642-1 Rating: moderate References: #1186918 Cross-References: CVE-2021-34557 CVSS scores: CVE-2021-34557 (NVD) : 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-34557 (SUSE): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for xscreensaver fixes the following issues: - CVE-2021-34557: Fixed potential crash and unlock while disconnecting video output with more than 10 monitors (bsc#1186918) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-2642=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): xscreensaver-5.22-8.3.1 xscreensaver-data-5.22-8.3.1 xscreensaver-data-debuginfo-5.22-8.3.1 xscreensaver-debuginfo-5.22-8.3.1 xscreensaver-debugsource-5.22-8.3.1 References: https://www.suse.com/security/cve/CVE-2021-34557.html https://bugzilla.suse.com/1186918 . A patch has been released for a significant security vulnerability in xscreensaver. Users should promptly apply the update SUSE-SLE-SERVER-12-SP5-2022-2642-1. SUSE Security Update,xscreensaver Patch,security update,Linux Enterprise Server. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for xscreensaver ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2641-1 Rating: moderate References: #1186918 Cross-References: CVE-2021-34557 CVSS scores: CVE-2021-34557 (NVD) : 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-34557 (SUSE): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Storage 7.1 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for xscreensaver fixes the following issues: - CVE-2021-34557: Fixed potential crash and unlock while disconnecting video output with more than 10 monitors (bsc#1186918) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-2641=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-2641=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): xscreensaver-5.44-150000.5.6.1 xscreensaver-data-5.44-150000.5.6.1 xscreensaver-data-debuginfo-5.44-150000.5.6.1 xscreensaver-data-extra-5.44-150000.5.6.1 xscreensaver-data-extra-debuginfo-5.44-150000.5.6.1 xscreensaver-debuginfo-5.44-150000.5.6.1 xscreensaver-debugsource-5.44-150000.5.6.1 - openSUSE Leap 15.3 (noarch): xscreensaver-lang-5.44-150000.5.6.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): xscreensaver-5.44-150000.5.6.1 xscreensaver-data-5.44-150000.5.6.1 xscreensaver-data-debuginfo-5.44-150000.5.6.1 xscreensaver-debuginfo-5.44-150000.5.6.1 xscreensaver-debugsource-5.44-150000.5.6.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (noarch): xscreensaver-lang-5.44-150000.5.6.1 References: https://www.suse.com/security/cve/CVE-2021-34557.html https://bugzilla.suse.com/1186918 . Ubuntu releases a patch for gnome-screensaver handling a vulnerability found in several Linux operating systems.. SUSE Security Update, xscreensaver Patch, Linux Security Fix. . LinuxSecurity.com Team
A potential security flaw was found on xscreensaver 5.45 which may cause buffer overflow or crash xscreensaver daemon. This vulnerability was assigned as CVE-2021-34557. This new rpm should fix this issue. Note that this issue does not affect xscreensaver 6.00 and above, so Fedora 34 xscreensaver is not affected.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-5af4452ffd 2021-08-19 01:10:36.707704 --------------------------------------------------------------------------------Name : xscreensaver Product : Fedora 33 Version : 5.45 Release : 2.fc33 URL : / Summary : X screen saver and locker Description : A modular screen saver and locker for the X Window System. More than 200 display modes are included in this package. This is a metapackage for installing all default packages related to XScreenSaver. --------------------------------------------------------------------------------Update Information: A potential security flaw was found on xscreensaver 5.45 which may cause buffer overflow or crash xscreensaver daemon. This vulnerability was assigned as CVE-2021-34557. This new rpm should fix this issue. Note that this issue does not affect xscreensaver 6.00 and above, so Fedora 34 xscreensaver is not affected. --------------------------------------------------------------------------------ChangeLog: * Tue Aug 10 2021 Mamoru TASAKA - 1:5.45-2 - update_screen_layout: fix CVE-2021-34557 (bug 1974194) --------------------------------------------------------------------------------References: [ 1 ] Bug #1974194 - CVE-2021-34557 XScreenSaver: buffer overflow in update_screen_layout() allows an attacker to bypass the standard screen lock authentication https://bugzilla.redhat.com/show_bug.cgi?id=1974194 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2021-5af4452ffd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An issue allowing to cause crash and locked screen bypass (CVE-2021-34557). References: - https://bugs.mageia.org/show_bug.cgi?id=29086 - https://www.openwall.com/lists/oss-security/2021/06/05/1 . MGASA-2021-0278 - Updated xscreensaver packages fix security vulnerability Publication date: 23 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0278.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-34557 An issue allowing to cause crash and locked screen bypass (CVE-2021-34557). References: - https://bugs.mageia.org/show_bug.cgi?id=29086 - https://www.openwall.com/lists/oss-security/2021/06/05/1 - https://www.openwall.com/lists/oss-security/2021/06/11/1 - https://www.cve.org/CVERecord?id=CVE-2021-34557 SRPMS: - 8/core/xscreensaver-5.45-1.4.mga8 - 8/tainted/xscreensaver-5.45-1.4.mga8.tainted . Mageia 8 XScreensaver Patch Resolves Crash Problems And Fixes Screen Bypass Security Flaws. xscreensaver security,mageia update,screen bypass,security patch. . Severity: Critical. LinuxSecurity.com Team
A security flaw was found that xscreensaver aborts in some case with dual screen and unplugging one of them. This new rpm should fix the issue.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-0d0df8d770 2015-11-05 17:27:39.106854 -------------------------------------------------------------------------------- Name : xscreensaver Product : Fedora 22 Version : 5.34 Release : 1.fc22 URL : / Summary : X screen saver and locker Description : A modular screen saver and locker for the X Window System. More than 200 display modes are included in this package. This is a metapackage for installing all default packages related to XScreenSaver. -------------------------------------------------------------------------------- Update Information: A security flaw was found that xscreensaver aborts in some case with dual screen and unplugging one of them. This new rpm should fix the issue. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1274452 - Xscreensaver lock bypass https://bugzilla.redhat.com/show_bug.cgi?id=1274452 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update xscreensaver' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
A security flaw was found that xscreensaver aborts in some case with dual screen and unplugging one of them. This new rpm should fix the issue.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-adfd729dbc 2015-11-05 17:26:09.284863 -------------------------------------------------------------------------------- Name : xscreensaver Product : Fedora 21 Version : 5.34 Release : 1.fc21 URL : / Summary : X screen saver and locker Description : A modular screen saver and locker for the X Window System. More than 200 display modes are included in this package. This is a metapackage for installing all default packages related to XScreenSaver. -------------------------------------------------------------------------------- Update Information: A security flaw was found that xscreensaver aborts in some case with dual screen and unplugging one of them. This new rpm should fix the issue. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1274452 - Xscreensaver lock bypass https://bugzilla.redhat.com/show_bug.cgi?id=1274452 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update xscreensaver' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
The system could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-2789-1 November 03, 2015 xscreensaver vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: The system could be made to expose sensitive information. Software Description: - xscreensaver: Automatic screensaver for X Details: It was discovered that XScreenSaver incorrectly handled unplugging an external monitor. An attacker with physical access could use this flaw to gain access to a locked session. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: xscreensaver 5.15-2ubuntu1.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2789-1 CVE-2015-8025 Package Information: https://launchpad.net/ubuntu/+source/xscreensaver/5.15-2ubuntu1.1 . =========================================================================Ubuntu Security Notice USN-. system, expose, sensitive, information, ==========================================. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.