Bug#989508: xscreensaver: Disconnecting a video output can cause XScreenSaver to crash and unlock

2021-06-14 Thread Salvatore Bonaccorso
Hi Tormod, On Mon, Jun 14, 2021 at 11:38:34PM +0200, Tormod Volden wrote: > This issue is marked as affecting 5.42+dfsg1-1 in buster (and even > stretch) in our CVE tracker, however the openwall report says: > > "The issue affects only XScreenSaver version 5.45. Versions 5.44 and > older, as

Bug#989508: xscreensaver: Disconnecting a video output can cause XScreenSaver to crash and unlock

2021-06-14 Thread Tormod Volden
This issue is marked as affecting 5.42+dfsg1-1 in buster (and even stretch) in our CVE tracker, however the openwall report says: "The issue affects only XScreenSaver version 5.45. Versions 5.44 and older, as well as 6.00, are not affected." Tormod

Bug#989508: xscreensaver: Disconnecting a video output can cause XScreenSaver to crash and unlock

2021-06-06 Thread Tormod Volden
On Sun, Jun 6, 2021 at 12:56 PM Tormod Volden wrote: > > I'll take a look at this now. We might want to include this in 5.45+dfsg1-2. > I have included the fix from Qubes-OS, pushed to salsa in commit 60304c21. I did some testing by plugging and unplugging an external monitor around 19 times.

Bug#989508: xscreensaver: Disconnecting a video output can cause XScreenSaver to crash and unlock

2021-06-06 Thread Tormod Volden
I'll take a look at this now. We might want to include this in 5.45+dfsg1-2. Tormod On Sat, Jun 5, 2021 at 8:51 PM Salvatore Bonaccorso wrote: > > On oss-security mailinglist an issue with xscreensaver has been > published which seems to be specific to the 4.45 version (and not > affecting

Bug#989508: xscreensaver: Disconnecting a video output can cause XScreenSaver to crash and unlock

2021-06-05 Thread Salvatore Bonaccorso
Source: xscreensaver Version: 5.45+dfsg1-1 Severity: important Tags: security upstream fixed-upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi On oss-security mailinglist an issue with xscreensaver has been published which seems to be specific to the 4.45 version (and not