VDB

CVE-2021-34557

CVE-2021-34557 PUBLISHED

XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in update_screen_layout() allows an attacker to bypass the standard screen lock authentication mechanism by crashing XScreenSaver. The attacker must physically disconnect many video outputs.

EPSS 0.17% · 38.4th percentile

Risk Scores

EPSS Score
0.17%
38.4th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSxscreensaver0, *
Ubuntu:20.04:LTSxscreensaver5.42+dfsg1-1ubuntu1, 0
Ubuntu:18.04:LTSxscreensaver0, 5.36-1ubuntu1
Ubuntu:16.04:LTSxscreensaver5.34-2ubuntu1, 5.34-1ubuntu1, 5.30-1ubuntu1

Timeline

  • Jun 10, 2021 CVE Published
  • Jun 11, 2021 EPSS Score
  • Aug 12, 2021 EPSS Score
  • Oct 11, 2021 EPSS Score
  • Dec 11, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 10, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 11, 2022 EPSS Score
  • Jun 11, 2022 EPSS Score
  • Aug 12, 2022 EPSS Score
  • Oct 12, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›