CVE-2007-3920

GNOME screensaver <2.20 - Privilege Escalation

Title source: llm
STIX 2.1

Description

GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.

References (15)

Core 15
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=363061
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10192
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-537-2
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=357071
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30715
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/37410
Patch vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-537-1
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26188
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0485.html
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27381
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28627
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30329

Scores

EPSS 0.0005
EPSS Percentile 16.1%

Details

Status published
Products (2)
compiz/compiz
gnome/screensaver 2.20
Published Oct 29, 2007
Tracked Since Feb 18, 2026