Vulnerability Name: | CVE-2009-4641 (CCN-56714) | ||||||||
Assigned: | 2009-11-02 | ||||||||
Published: | 2009-11-02 | ||||||||
Updated: | 2010-07-07 | ||||||||
Summary: | gnome-screensaver 2.28.0 does not resume adherence to its activation settings after an inhibiting application becomes unavailable on the session bus, which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)
1.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-4641 Source: MANDRIVA Type: UNKNOWN MDVSA-2010:040 Source: CCN Type: OSVDB ID: 61117 gnome-screensaver on Ubuntu Linux Idle Timer Re-enable Weakness Source: CCN Type: BID-37240 gnome-screensaver Timeout Security Bypass Vulnerability Source: CCN Type: USN-866-1 gnome-screensaver vulnerability Source: UBUNTU Type: UNKNOWN USN-866-1 Source: CCN Type: GNOME Bugzilla Bug 600488 Totem is leaking session inhibitors Source: CONFIRM Type: Patch https://bugzilla.gnome.org/show_bug.cgi?id=600488 Source: XF Type: UNKNOWN gnomescreensaver-sessionbus-sec-bypass(56714) Source: CONFIRM Type: UNKNOWN https://launchpad.net/bugs/411350 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |