PT-2010-1452 · Canonical+2 · Ubuntu+3
Marc Deslauriers
+1
·
Publicado
2010-02-11
·
Atualizado
2010-03-22
·
CVE-2009-4642
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
gnome-screensaver version 2.26.1
Description
The issue allows physically proximate attackers to access an unattended workstation where screen locking was intended, due to gnome-screensaver relying on the gnome-session D-Bus interface to determine session idle time. This occurs even when using an Xfce desktop, such as Xubuntu or Mythbuntu.
Recommendations
For gnome-screensaver version 2.26.1, consider disabling the use of the gnome-session D-Bus interface for determining session idle time as a temporary workaround, until a patch is available. Restrict access to the workstation to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mythbuntu
Xfce
Ubuntu
Gnome-Screensaver