← Back

CVE-2016-10894

nvd nist
Published: Aug 16, 2019Modified: Nov 21, 2024

JSON object

Loading...
4.6
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 0.9 / Impact: 3.6
Source: NVD

Description

xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such as Chromium via events such as pan scrolling, "pinch and zoom" gestures, or even regular mouse clicks (by depressing the touchpad once and then clicking with a different finger).

Affected (2)

Xtrlock
1 product
Debian Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.10
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0

Related CWEs

References (4)

Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.