CVE-2009-4997: High severity Gnome Power Manager vulnerability
gnome-power-manager 2.27.92 does not properly implement the lockonsuspend and lockonhibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532. NOTE: this issue exists because of a regression that followed a gnome-power-manager fix a few years earlier.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4997?
CVE-2009-4997 is classified as a moderate severity vulnerability.
How do I fix CVE-2009-4997?
To fix CVE-2009-4997, update GNOME Power Manager to a patched version that addresses the lock_on_suspend and lock_on_hibernate settings.
What are the potential impacts of CVE-2009-4997?
The potential impact of CVE-2009-4997 includes unauthorized access to an unattended laptop, as the screen may not lock on suspend or hibernate.
Which software versions are affected by CVE-2009-4997?
CVE-2009-4997 specifically affects GNOME Power Manager version 2.27.92.
Who is at risk for CVE-2009-4997?
Users of GNOME Power Manager version 2.27.92 who often suspend or hibernate their laptops are at risk for CVE-2009-4997.