First published: Fri Aug 07 2009(Updated: )
XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Solaris | =snv_01 | |
Solaris | =snv_02 | |
Solaris | =snv_03 | |
Solaris | =snv_04 | |
Solaris | =snv_05 | |
Solaris | =snv_06 | |
Solaris | =snv_07 | |
Solaris | =snv_08 | |
Solaris | =snv_09 | |
Solaris | =snv_10 | |
Solaris | =snv_11 | |
Solaris | =snv_12 | |
Solaris | =snv_13 | |
Solaris | =snv_14 | |
Solaris | =snv_15 | |
Solaris | =snv_16 | |
Solaris | =snv_17 | |
Solaris | =snv_18 | |
Solaris | =snv_19 | |
Solaris | =snv_20 | |
Solaris | =snv_21 | |
Solaris | =snv_22 | |
Solaris | =snv_23 | |
Solaris | =snv_24 | |
Solaris | =snv_25 | |
Solaris | =snv_26 | |
Solaris | =snv_27 | |
Solaris | =snv_28 | |
Solaris | =snv_29 | |
Solaris | =snv_30 | |
Solaris | =snv_31 | |
Solaris | =snv_32 | |
Solaris | =snv_33 | |
Solaris | =snv_34 | |
Solaris | =snv_35 | |
Solaris | =snv_36 | |
Solaris | =snv_37 | |
Solaris | =snv_38 | |
Solaris | =snv_39 | |
Solaris | =snv_40 | |
Solaris | =snv_41 | |
Solaris | =snv_42 | |
Solaris | =snv_43 | |
Solaris | =snv_44 | |
Solaris | =snv_45 | |
Solaris | =snv_46 | |
Solaris | =snv_47 | |
Solaris | =snv_48 | |
Solaris | =snv_49 | |
Solaris | =snv_50 | |
Solaris | =snv_51 | |
Solaris | =snv_52 | |
Solaris | =snv_53 | |
Solaris | =snv_54 | |
Solaris | =snv_55 | |
Solaris | =snv_56 | |
Solaris | =snv_57 | |
Solaris | =snv_58 | |
Solaris | =snv_59 | |
Solaris | =snv_60 | |
Solaris | =snv_61 | |
Solaris | =snv_62 | |
Solaris | =snv_63 | |
Solaris | =snv_64 | |
Solaris | =snv_65 | |
Solaris | =snv_66 | |
Solaris | =snv_67 | |
Solaris | =snv_68 | |
Solaris | =snv_69 | |
Solaris | =snv_70 | |
Solaris | =snv_71 | |
Solaris | =snv_72 | |
Solaris | =snv_73 | |
Solaris | =snv_74 | |
Solaris | =snv_75 | |
Solaris | =snv_76 | |
Solaris | =snv_77 | |
Solaris | =snv_78 | |
Solaris | =snv_79 | |
Solaris | =snv_80 | |
Solaris | =snv_81 | |
Solaris | =snv_82 | |
Solaris | =snv_83 | |
Solaris | =snv_84 | |
Solaris | =snv_85 | |
Solaris | =snv_86 | |
Solaris | =snv_87 | |
Solaris | =snv_88 | |
Solaris | =snv_89 | |
Solaris | =snv_90 | |
Solaris | =snv_91 | |
Solaris | =snv_92 | |
Solaris | =snv_93 | |
Solaris | =snv_94 | |
Solaris | =snv_95 | |
Solaris | =snv_96 | |
Solaris | =snv_97 | |
Solaris | =snv_98 | |
Solaris | =snv_99 | |
Solaris | =snv_100 | |
Solaris | =snv_101 | |
Solaris | =snv_102 | |
Solaris | =snv_103 | |
Solaris | =snv_104 | |
Solaris | =snv_105 | |
Solaris | =snv_106 | |
Solaris | =snv_107 | |
Solaris | =snv_108 | |
Solaris | =snv_109 | |
Solaris | =snv_110 | |
Solaris | =snv_111 | |
Solaris | =snv_112 | |
Solaris | =snv_113 | |
Solaris | =snv_114 | |
Solaris | =snv_115 | |
Solaris | =snv_116 | |
Solaris | =snv_117 | |
Solaris | =snv_118 | |
Solaris | =snv_119 | |
Oracle Solaris SPARC | =9.0 | |
Oracle Solaris SPARC | =10 | |
Solaris | =snv_01 | |
Solaris | =snv_02 | |
Solaris | =snv_03 | |
Solaris | =snv_04 | |
Solaris | =snv_05 | |
Solaris | =snv_06 | |
Solaris | =snv_07 | |
Solaris | =snv_08 | |
Solaris | =snv_09 | |
Solaris | =snv_10 | |
Solaris | =snv_11 | |
Solaris | =snv_12 | |
Solaris | =snv_13 | |
Solaris | =snv_14 | |
Solaris | =snv_15 | |
Solaris | =snv_16 | |
Solaris | =snv_17 | |
Solaris | =snv_18 | |
Solaris | =snv_19 | |
Solaris | =snv_20 | |
Solaris | =snv_21 | |
Solaris | =snv_22 | |
Solaris | =snv_23 | |
Solaris | =snv_24 | |
Solaris | =snv_25 | |
Solaris | =snv_26 | |
Solaris | =snv_27 | |
Solaris | =snv_28 | |
Solaris | =snv_29 | |
Solaris | =snv_30 | |
Solaris | =snv_31 | |
Solaris | =snv_32 | |
Solaris | =snv_33 | |
Solaris | =snv_34 | |
Solaris | =snv_35 | |
Solaris | =snv_36 | |
Solaris | =snv_37 | |
Solaris | =snv_38 | |
Solaris | =snv_39 | |
Solaris | =snv_40 | |
Solaris | =snv_41 | |
Solaris | =snv_42 | |
Solaris | =snv_43 | |
Solaris | =snv_44 | |
Solaris | =snv_45 | |
Solaris | =snv_46 | |
Solaris | =snv_47 | |
Solaris | =snv_48 | |
Solaris | =snv_49 | |
Solaris | =snv_50 | |
Solaris | =snv_51 | |
Solaris | =snv_52 | |
Solaris | =snv_53 | |
Solaris | =snv_54 | |
Solaris | =snv_55 | |
Solaris | =snv_56 | |
Solaris | =snv_57 | |
Solaris | =snv_58 | |
Solaris | =snv_59 | |
Solaris | =snv_60 | |
Solaris | =snv_61 | |
Solaris | =snv_62 | |
Solaris | =snv_63 | |
Solaris | =snv_64 | |
Solaris | =snv_65 | |
Solaris | =snv_66 | |
Solaris | =snv_67 | |
Solaris | =snv_68 | |
Solaris | =snv_69 | |
Solaris | =snv_70 | |
Solaris | =snv_71 | |
Solaris | =snv_72 | |
Solaris | =snv_73 | |
Solaris | =snv_74 | |
Solaris | =snv_75 | |
Solaris | =snv_76 | |
Solaris | =snv_77 | |
Solaris | =snv_78 | |
Solaris | =snv_79 | |
Solaris | =snv_80 | |
Solaris | =snv_81 | |
Solaris | =snv_100 | |
Solaris | =snv_101 | |
Solaris | =snv_102 | |
Solaris | =snv_103 | |
Solaris | =snv_104 | |
Solaris | =snv_105 | |
Solaris | =snv_106 | |
Solaris | =snv_107 | |
Solaris | =snv_108 | |
Solaris | =snv_109 | |
Solaris | =snv_110 | |
Solaris | =snv_111 | |
Solaris | =snv_112 | |
Solaris | =snv_113 | |
Solaris | =snv_114 | |
Solaris | =snv_115 | |
Solaris | =snv_116 | |
Solaris | =snv_117 | |
Solaris | =snv_118 | |
Solaris | =snv_119 | |
Oracle Solaris SPARC | =8.0 | |
Oracle Solaris SPARC | =9.0 | |
Oracle Solaris SPARC | =10 | |
X.org X.org | =6.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2711 has been classified as a medium severity vulnerability.
To fix CVE-2009-2711, update to a version of XScreenSaver that rectifies this issue, ensuring to use patched Solaris versions.
CVE-2009-2711 affects users of Sun Solaris 9, Solaris 10, and OpenSolaris prior to snv_120.
An attacker exploiting CVE-2009-2711 can gain access to sensitive information displayed in popup windows while the screen is locked.
CVE-2009-2711 allows physically proximate attackers to read sensitive data in popup windows even when the system is secured.