CVE-2013-4427

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
19/05/2014
Last modified:
19/05/2014

Description

pyxtrlock before 0.2 does not properly check the return values of the (1) xcb_grab_pointer and (2) xcb_grab_keyboard XCB library functions, which allows physically proximate attackers to gain access to the keyboard or mouse without unlocking the screen via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:leon_weber:pyxtrlock:*:-:*:*:*:*:*:* 0.1 (including)
cpe:2.3:a:leon_weber:pyxtrlock:0.1:beta:*:*:*:*:*:*