English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Sun Solaris XScreenSaver Pop-up Windows Security Bypass


Secunia ID

SA37248

CVE-ID

CVE-2009-3746

Release Date

04 Nov 2009

Last Change

09 Nov 2009

Criticality

Not Critical

Solution Status

Vendor Patch

Where

Local system

Impact
Security Bypass

This covers vulnerabilities or security issues where malicious users or people can bypass certain security mechanisms of the application.

The actual impact varies significantly depending on the design and purpose of the affected application.

Description

A weakness has been reported in Sun Solaris, which can be exploited by malicious people with physical access to the system to potentially bypass certain security restrictions.

The problem is that XScreenSaver allows certain pop-up windows to appear when the screen is locked and the accessibility
feature is enabled.

NOTE: The weakness was introduced in patches 120094-27 and 120095-27.

The weakness is reported in Solaris 10 for both the SPARC and x86 platforms.

Solution

Apply patches.

-- SPARC Platform --

Solaris 10:
Apply patch 120094-29 or later.

-- x86 Platform --

Solaris 10:
Apply patch 120095-29 or later.

Reported by

Reported by the vendor.

Original Advisory

http://sunsolve.sun.com/search/document.do?assetkey=1-66-268288-1