First published: Tue Sep 07 2010(Updated: )
gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Power Manager | =2.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7240 is classified as a moderate severity vulnerability due to its potential to allow physical access to an unattended laptop.
To resolve CVE-2006-7240, ensure that the lock_on_suspend and lock_on_hibernate settings are properly configured in the gnome-power-manager settings.
CVE-2006-7240 specifically affects Gnome Power Manager version 2.14.0.
The impact of CVE-2006-7240 is that it could allow an attacker with physical access to bypass the screen lock on a suspended or hibernated machine.
A possible workaround for CVE-2006-7240 is to manually lock the screen before suspending or hibernating the device.