PT-2010-1799 · Xfce · Xfce4-Session
Christoph Wickert
·
Published
2010-09-07
·
Updated
2024-08-07
·
CVE-2009-4996
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Xfce4-session version 4.5.91
Description
The issue concerns Xfce4-session not locking the screen when the suspend or hibernate button is pressed. This could potentially allow physically proximate attackers to access an unattended laptop via a resume action. It is noted that there is no general agreement on whether this behavior constitutes a vulnerability, as separate control over locking can be equally or more secure in certain threat environments.
Recommendations
For Xfce4-session version 4.5.91, consider configuring the system to lock the screen manually when suspending or hibernating to minimize potential risks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xfce4-Session