gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensaver to crash and access the session via the Ctl+Alt+Keypad-Multiply keyboard sequence, which removes the grab from gnome. The vulnerability has reportedly been fixed in version 2.14.
Publication date: Tue, 21 Mar 2006 07:06:00 +0000