PT-2010-1452 · Canonical+2 · Ubuntu+3
Marc Deslauriers
+1
·
Published
2010-02-11
·
Updated
2010-03-22
·
CVE-2009-4642
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
gnome-screensaver version 2.26.1
Description
The issue allows physically proximate attackers to access an unattended workstation where screen locking was intended, due to gnome-screensaver relying on the gnome-session D-Bus interface to determine session idle time. This occurs even when using an Xfce desktop, such as Xubuntu or Mythbuntu.
Recommendations
For gnome-screensaver version 2.26.1, consider disabling the use of the gnome-session D-Bus interface for determining session idle time as a temporary workaround, until a patch is available. Restrict access to the workstation to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mythbuntu
Xfce
Ubuntu
Gnome-Screensaver