Created attachment 109890 [details] Proposed patch for this issue.
Debian reported this to vendor-sec on 2005-01-16 -------------------------------------- This only affects KDE older than 3.0.5 -------------------------------------- Raphaël Enrici discovered that the KDE screensaver can crash under certain local circumstances. This can be exploited by an attacker with physical access to the workstation to take over the desktop session. When kscreensaver has locked the screen and the user disappears getpwuid() returns NULL which is not taken care of. As a result the screensaver will crash. In a version more recent than 2.2 the screensaver and locker are differnt processes, but the locker has the same issues, until it was fixed in November 2002 and made it into KDE 3.0.5. For older versions of KDE the attached patch or a forward port will fix this problem. This issue only affects RHEL2.1
it's fixed in kdebase-2.2.2-14
Now public
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2005-009.html