CVE-2009-1276: Infoleak
XScreenSaver in Sun Solaris 10 and OpenSolaris before snv109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, as demonstrated by Thunderbird new-mail notifications.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1276?
CVE-2009-1276 has been classified as a medium severity vulnerability due to its potential to expose sensitive information.
How can CVE-2009-1276 be exploited?
CVE-2009-1276 can be exploited by physically proximate attackers who can access the screen containing locked popup windows.
How do I fix CVE-2009-1276?
To mitigate CVE-2009-1276, users should update their XScreenSaver and related software to the latest versions where this vulnerability is addressed.
Which systems are affected by CVE-2009-1276?
CVE-2009-1276 affects various versions of Sun Solaris and OpenSolaris, particularly versions before snv_109, and Solaris 8 and 9 with GNOME versions 2.0 or 2.0.2.
What kind of information can be accessed through CVE-2009-1276?
CVE-2009-1276 allows attackers to read sensitive information displayed in popup windows, such as email notifications, while the screen is locked.