Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-4642
HistoryFeb 11, 2010 - 12:00 a.m.

CVE-2009-4642

2010-02-1100:00:00
ubuntu.com
ubuntu.com
12

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.001

Percentile

27.5%

gnome-screensaver 2.26.1 relies on the gnome-session D-Bus interface to
determine session idle time, even when an Xfce desktop such as Xubuntu or
Mythbuntu is used, which allows physically proximate attackers to access an
unattended workstation on which screen locking had been intended.

Bugs

Notes

Author Note
kees While it looks like a gnome-screensaver bug, for stable releases, this is an issue primarily for xfce, which doesn’t use g-ss correctly. Going forward, gnome-session has been added to the g-ss package deps so that the issue is more obvious to integration attempts of g-ss.

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.001

Percentile

27.5%

Related for UB:CVE-2009-4642