PT-2010-4085 · Lxde · Lxsession
Published
2010-09-03
·
Updated
2024-08-07
·
CVE-2010-2532
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
lxsession versions in LXDE, as used on SUSE openSUSE 11.3 and other platforms
Description
The issue concerns the behavior of lxsession-logout in LXDE when the Suspend or Hibernate button is pressed. It does not lock the screen, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action. There is a note that there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, behavior in some threat environments.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lxsession