CVE-2007-6389 Information

Description

The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might allow local users to read the clipboard contents and X selection data for a locked session by using ctrl-V.

Reference

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=455484 http://bugzilla.gnome.org/show_bug.cgi?id=482159 http://bugzilla.gnome.org/show_bug.cgi?id=503005 http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html http://secunia.com/advisories/29595 http://secunia.com/advisories/29666 http://secunia.com/advisories/31687 http://secunia.com/advisories/32691 http://www.mandriva.com/security/advisories?name=MDVSA-2008:135 http://www.securityfocus.com/bid/30096 http://www.ubuntu.com/usn/USN-669-1 https://bugs.launchpad.net/ubuntu/+source/gnome-screensaver/+bug/146862 https://bugzilla.redhat.com/show_bug.cgi?id=421461 https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00020.html https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00078.html

Share on: