First published: Thu Feb 11 2010(Updated: )
gnome-screensaver 2.28.0 does not resume adherence to its activation settings after an inhibiting application becomes unavailable on the session bus, which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Screensaver | =2.28.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4641 is considered a medium severity vulnerability.
To fix CVE-2009-4641, you should upgrade to a newer version of GNOME screensaver that addresses this vulnerability.
CVE-2009-4641 is caused by the GNOME screensaver not resuming its activation settings when an inhibiting application becomes unavailable.
Users of GNOME screensaver version 2.28.0 are affected by CVE-2009-4641.
CVE-2009-4641 can be exploited by physically proximate attackers who gain access to an unattended workstation due to the screensaver not locking.