CVE-2009-4641: High severity Gnome screensaver vulnerability
gnome-screensaver 2.28.0 does not resume adherence to its activation settings after an inhibiting application becomes unavailable on the session bus, which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4641?
CVE-2009-4641 is considered a medium severity vulnerability.
How do I fix CVE-2009-4641?
To fix CVE-2009-4641, you should upgrade to a newer version of GNOME screensaver that addresses this vulnerability.
What causes CVE-2009-4641?
CVE-2009-4641 is caused by the GNOME screensaver not resuming its activation settings when an inhibiting application becomes unavailable.
Who is affected by CVE-2009-4641?
Users of GNOME screensaver version 2.28.0 are affected by CVE-2009-4641.
How can CVE-2009-4641 be exploited?
CVE-2009-4641 can be exploited by physically proximate attackers who gain access to an unattended workstation due to the screensaver not locking.