CVE-2012-1620

low
Published 2012-07-12 · Modified 2026-04-29
CVSS v3
CVSS v2
3.6
VIR risk
3.6

Description

slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive information by pressing a button, which reveals the desktop and active windows.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-1620

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/48700

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://hg.suckless.org/slock/rev/891a4984aba6

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed39-1
debian debianbullseyefixed39-1
debian debianforkyfixed39-1
debian debiansidfixed39-1
debian debiantrixiefixed39-1

Application impact

VendorProductVersionsFixed
sucklessslock0.9

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.