CVE-2007-3920

GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.html
http://secunia.com/advisories/27381 Patch Vendor Advisory
http://secunia.com/advisories/28627
http://secunia.com/advisories/30329
http://secunia.com/advisories/30715
http://www.redhat.com/support/errata/RHSA-2008-0485.html
http://www.securityfocus.com/bid/26188 Patch
http://www.ubuntu.com/usn/usn-537-1 Patch
http://www.ubuntu.com/usn/usn-537-2
https://bugzilla.redhat.com/show_bug.cgi?id=357071
https://bugzilla.redhat.com/show_bug.cgi?id=363061
https://exchange.xforce.ibmcloud.com/vulnerabilities/37410
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10192
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00811.html
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00841.html
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.html
http://secunia.com/advisories/27381 Patch Vendor Advisory
http://secunia.com/advisories/28627
http://secunia.com/advisories/30329
http://secunia.com/advisories/30715
http://www.redhat.com/support/errata/RHSA-2008-0485.html
http://www.securityfocus.com/bid/26188 Patch
http://www.ubuntu.com/usn/usn-537-1 Patch
http://www.ubuntu.com/usn/usn-537-2
https://bugzilla.redhat.com/show_bug.cgi?id=357071
https://bugzilla.redhat.com/show_bug.cgi?id=363061
https://exchange.xforce.ibmcloud.com/vulnerabilities/37410
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10192
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00811.html
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00841.html
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:ubuntu:ubuntu_linux:7.10:*:amd64:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:7.10:*:i386:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:7.10:*:powerpc:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:7.10:*:sparc:*:*:*:*:*
OR cpe:2.3:a:compiz:compiz:*:*:*:*:*:*:*:*
cpe:2.3:a:gnome:screensaver:2.20:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-10-29 21:46

Updated : 2025-04-09 00:30


NVD link : CVE-2007-3920

Mitre link : CVE-2007-3920

CVE.ORG link : CVE-2007-3920


JSON object : View

Products Affected

gnome

  • screensaver

compiz

  • compiz

ubuntu

  • ubuntu_linux