slock 0.9 does not properly handle the XRaiseWindow event when...
Vulnerability Description
slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive information by pressing a button, which reveals the desktop and active windows.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-1620
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugs.gentoo.org/show_bug.cgi?id=401645
- http://www.openwall.com/lists/oss-security/2012/04/06/2
- http://www.openwall.com/lists/oss-security/2012/04/06/1
- http://secunia.com/advisories/48700
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74666
- http://www.osvdb.org/81035
- http://www.securityfocus.com/bid/52922
- http://hg.suckless.org/slock/rev/891a4984aba6
- https://bugzilla.redhat.com/show_bug.cgi?id=786310
Affected Vendor
suckless
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.