Advisories ยป MGASA-2013-0225

Updated xlockmore package fixes security vulnerability

Publication date: 21 Jul 2013
Modification date: 21 Jul 2013
Type: security
Affected Mageia releases : 3
CVE: CVE-2013-4143

Description

xlockmore before 5.43 contains a security flaw related to potential NULL
pointer dereferences when authenticating via glibc 2.17+'s crypt() function.
Under certain conditions the NULL pointers can trigger a crash in xlockmore
effectively bypassing the screen lock (CVE-2013-4143).
                

References

SRPMS

3/core