PT-2010-1452 · Canonical+2 · Ubuntu+3

Marc Deslauriers

+1

·

Published

2010-02-11

·

Updated

2010-03-22

·

CVE-2009-4642

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions gnome-screensaver version 2.26.1
Description The issue allows physically proximate attackers to access an unattended workstation where screen locking was intended, due to gnome-screensaver relying on the gnome-session D-Bus interface to determine session idle time. This occurs even when using an Xfce desktop, such as Xubuntu or Mythbuntu.
Recommendations For gnome-screensaver version 2.26.1, consider disabling the use of the gnome-session D-Bus interface for determining session idle time as a temporary workaround, until a patch is available. Restrict access to the workstation to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-4642

Affected Products

Mythbuntu
Xfce
Ubuntu
Gnome-Screensaver