Lucene search

K
cve[email protected]CVE-2009-3100
HistoryOct 03, 2022 - 4:23 p.m.

CVE-2009-3100

2022-10-0316:23:55
web.nvd.nist.gov
30
xscreensaver
solaris
opensolaris
denial of service
cve-2009-3100

4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:N/I:N/A:C

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.4%

xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv_109 through snv_122, and X11 6.4.1 on Solaris 8 does not properly handle Accessibility support, which allows local users to cause a denial of service (system hang) by locking the screen and then attempting to launch an Accessibility pop-up window, related to a regression in certain Solaris and OpenSolaris patches.

Affected configurations

NVD
Node
sunopensolarisMatchsnv_109sparc
OR
sunopensolarisMatchsnv_109x86
OR
sunopensolarisMatchsnv_110sparc
OR
sunopensolarisMatchsnv_110x86
OR
sunopensolarisMatchsnv_111sparc
OR
sunopensolarisMatchsnv_111x86
OR
sunopensolarisMatchsnv_112sparc
OR
sunopensolarisMatchsnv_112x86
OR
sunopensolarisMatchsnv_113sparc
OR
sunopensolarisMatchsnv_113x86
OR
sunopensolarisMatchsnv_114sparc
OR
sunopensolarisMatchsnv_114x86
OR
sunopensolarisMatchsnv_115sparc
OR
sunopensolarisMatchsnv_115x86
OR
sunopensolarisMatchsnv_116sparc
OR
sunopensolarisMatchsnv_116x86
OR
sunopensolarisMatchsnv_117sparc
OR
sunopensolarisMatchsnv_117x86
OR
sunopensolarisMatchsnv_118sparc
OR
sunopensolarisMatchsnv_118x86
OR
sunopensolarisMatchsnv_119sparc
OR
sunopensolarisMatchsnv_119x86
OR
sunopensolarisMatchsnv_120sparc
OR
sunopensolarisMatchsnv_120x86
OR
sunopensolarisMatchsnv_121sparc
OR
sunopensolarisMatchsnv_121x86
OR
sunopensolarisMatchsnv_122sparc
OR
sunopensolarisMatchsnv_122x86
OR
sunsolarisMatch9sparc
OR
sunsolarisMatch9x86
OR
sunsolarisMatch10sparc
OR
sunsolarisMatch10x86
Node
x.orgx11Match6.4.1
AND
sunsolarisMatch8sparc
OR
sunsolarisMatch8x86

4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:N/I:N/A:C

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.4%