Title : Redhat Security Update Fixes Compiz Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2008-1616 CVE ID : CVE-2007-3920
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-05-22
Technical Description
A vulnerability has been identified in various Redhat products, which could be exploited by local attackers to bypass security restrictions. This issue is caused by an error in Compiz when un-redirecting top-level fullscreen windows, which could allow attackers with physical access to gain access to a locked session.