CVE-2010-0732

NameCVE-2010-0732
Descriptiongdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances and consequently allows physically proximate attackers to bypass screen locking and access an unattended workstation by pressing the Enter key many times.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gtk+2.0 (PTS)buster2.24.32-3fixed
bookworm, bullseye2.24.33-2fixed
trixie2.24.33-3fixed
sid2.24.33-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gtk+2.0sourceetch(not affected)
gtk+2.0sourcelenny(not affected)
gtk+2.0source(unstable)2.18.5-1

Notes

[lenny] - gtk+2.0 <not-affected> (issue only exposed by gnome-screensaver 2.28)
[etch] - gtk+2.0 <not-affected> (issue only exposed by gnome-screensaver 2.28)
https://www.openwall.com/lists/oss-security/2010/02/12/1

Search for package or bug name: Reporting problems