driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "xscreensaver",
"binary_version": "5.15-3+deb7u1ubuntu0.1"
},
{
"binary_name": "xscreensaver-data",
"binary_version": "5.15-3+deb7u1ubuntu0.1"
},
{
"binary_name": "xscreensaver-data-extra",
"binary_version": "5.15-3+deb7u1ubuntu0.1"
},
{
"binary_name": "xscreensaver-gl",
"binary_version": "5.15-3+deb7u1ubuntu0.1"
},
{
"binary_name": "xscreensaver-gl-extra",
"binary_version": "5.15-3+deb7u1ubuntu0.1"
},
{
"binary_name": "xscreensaver-screensaver-bsod",
"binary_version": "5.15-3+deb7u1ubuntu0.1"
},
{
"binary_name": "xscreensaver-screensaver-webcollage",
"binary_version": "5.15-3+deb7u1ubuntu0.1"
}
]
}