CVE-2015-8025

low
Published 2015-11-10 · Modified 2026-05-06
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-8025

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2015-8025.html

OS impact

OSVersionStatusFixed in
suse slesaffected
ubuntu ubuntu12.04affected
debian debianbookwormfixed5.34-1
debian debianbullseyefixed5.34-1
debian debianforkyfixed5.34-1
debian debiansidfixed5.34-1
debian debiantrixiefixed5.34-1

Application impact

VendorProductVersionsFixed
xscreensaver_projectxscreensaver5.33

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.