Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Daily Reviews Summary 02/09/12
· 3 Advanced Tips & Tricks For Using Windows Explorer
· MySQL 5.5.20 for Debian 6
· How to Install Screenlets for Desktop Widgets in Linux Mint 12
· Microsoft, Google, and Apple talk up "fair and reasonable" patent license fees
· Latest Windows 8 and Windows 8 Server build numbers revealed
· 3 CentOS Updates
· 3 RHEL Updates
· European Apple resellers say lack of inventory is putting them out of business
· Latest Windows 8 Consumer Preview build number: 8225?

Upcoming News
· Athena Power AP-MFATX40P8 400 W Power Supply Review @ Hardware Secrets
· [Tech ARP] Desktop CPU Comparison Guide Rev. 11.7
· Swiftech H20-220 Edge HD Liquid Cooling Kit Review @ Legit Reviews
· Intel 520 Series Cherryville 240GB SSD Review @ HCW
· [CentOS-announce] CEBA-2012:0106 CentOS 5 selinux-policy Update
· Samsung NX 200 Review @ TechReviewSource.com
· OCZ RevoDrive 3 120GB SSD Review @ t-break
· OCZ Technology Octane 512GB Solid State Drive with 1.13 Performance Firmware
· Western Digital WD TV Live Media Player Review @ Bigbruin.com
· Hitachi Touro Desk Pro 3TB USB 3.0 External HDD Review @ Madshrimps

Linux Compatibility
· XPS L502X
· Slim Portable DVD Writer GP10
· AverTV Volar Green HD
· Dell Latitude E6420
· Canon CanoScan FB 636U
· Logitech QuickCam Pro 4000
· GeForce 7300 GT
· Umax Astra 4500 USB Scanner
· Photosmart Pro B9180
· kingston DataTraveler DTI/16GB

New Forum Topics
· Directx
by: Rajoo
on: 2012-02-06 21:29
0 replies, 113 views

· Code: Bad EIP Value
by: megatouchguy
on: 2012-01-28 06:27
0 replies, 355 views

· XP Pro crashes on start up
by: javien
on: 2012-01-17 12:38
6 replies, 2030 views

· Lan Wireless Access To Shared Folders Problem
by: MinusZero
on: 2012-01-09 06:45
2 replies, 2212 views

· Motherboard glitch
by: danleff
on: 2012-01-08 12:03
3 replies, 655 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » November 2008 » USN-669-1: gnome-screensaver vulnerabilities

USN-669-1: gnome-screensaver vulnerabilities

Posted by Bob on: 11/11/2008 09:30 PM [ Print | 0 comment(s) ]

A new gnome-screensaver vulnerabilities update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-669-1 November 11, 2008
gnome-screensaver vulnerabilities
CVE-2007-6389, CVE-2008-0887
==========================
==========================
=========

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 7.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
gnome-screensaver 2.14.3-0ubuntu1.1

Ubuntu 7.10:
gnome-screensaver 2.20.0-0ubuntu4.3

After a standard system upgrade you need to restart all user sessions on
your computer to effect the necessary changes.

Details follow:

It was discovered that the notify feature in gnome-screensaver could let
a local attacker read the clipboard contents of a locked session by
using Ctrl-V. (CVE-2007-6389)

Alan Matsuoka discovered that gnome-screensaver did not properly handle
network outages when using a remote authentication service. During a
network interruption, or by disconnecting the network cable, a local
attacker could gain access to locked sessions. (CVE-2008-0887)


Updated packages for Ubuntu 6.06 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.14.3-0ubuntu1.1.diff.gz
Size/MD5: 14632 858a17bd71cf1969f89c9f7248840e0b
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.14.3-0ubuntu1.1.dsc
Size/MD5: 1515 100a66b14d50912bd73b49b6915d849b
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.14.3.orig.tar.gz
Size/MD5: 2122211 9c95c9d0ad4c44a215546dd4b95992b0

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.14.3-0ubuntu1.1_amd64.deb
Size/MD5: 1502090 d5bfdd6505afe949c6414fb01dab0bb9

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.14.3-0ubuntu1.1_i386.deb
Size/MD5: 1483824 bcb42c8bb0a73fbc06c5a465a75fa299

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.14.3-0ubuntu1.1_powerpc.deb
Size/MD5: 1499086 d7e65422d70d2ff6405b0472f03b1c1f

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.14.3-0ubuntu1.1_sparc.deb
Size/MD5: 1486326 bff6d9f48780721f2621a0c6895aa143

Updated packages for Ubuntu 7.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.20.0-0ubuntu4.3.diff.gz
Size/MD5: 25605 044d070d183f0e073dc1ac81945b0cc5
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.20.0-0ubuntu4.3.dsc
Size/MD5: 1695 472b10fdbd46177cbe20b58350265d64
http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.20.0.orig.tar.gz
Size/MD5: 2320018 db71d89c66fa3a96b3b276403b5bb723

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.20.0-0ubuntu4.3_amd64.deb
Size/MD5: 1587388 6655526c8225d3b139eb36c1cbbf948a

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.20.0-0ubuntu4.3_i386.deb
Size/MD5: 1570386 456e6a56f46efac8de675aa906bf70c2

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/g/gnome-screensaver/gnome-screensaver=
_2.20.0-0ubuntu4.3_lpia.deb
Size/MD5: 1569166 c7f1ce8eeee0127cd557a78cf9591b36

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.20.0-0ubuntu4.3_powerpc.deb
Size/MD5: 1606010 a65b33b3a95a7d23bcbdd5e894785852

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/pool/main/g/gnome-screensaver/gnome-s=
creensaver_2.20.0-0ubuntu4.3_sparc.deb
Size/MD5: 1576698 1566098fa61738a75ecaf0c98886eac1



--=-4IVhQM1uIY3V+c53vAYj
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEABECAAYFAkkZ6YMACgkQLMAs/0C4zNqEIQCdEUWEt3CYBpeUaE+twytiUGPA
g/gAnRoDkRs4ytcBYz2oK0i1G2Exq61n
=WxiA
-----END PGP SIGNATURE-----


Bookmark and Share

« Overclocked Radeon HD 4870 X2 Shoot-Out: ASUS, MSI · Flawed AVG antivirus update cripples Windows XP PCs »

Linux Compatible » News » November 2008 » USN-669-1: gnome-screensaver vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2011 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition