CVE-2010-0414: High severity Gnome screensaver vulnerability

Published Feb 5, 2010
·
Updated

gnome-screensaver before 2.28.2 allows physically proximate attackers to bypass screen locking and access an unattended workstation by moving the mouse position to an external monitor and then disconnecting that monitor.

Other sources

Under certain circumstances it is possible to circumvent the security of screen locking functionality of gnome-screensaver by changing the systems physical monitor configuration.

Steps to reproduce:

1) Lock screen 2) Move mouse to removable monitor 3) hit escape key to cancel unlock dialog 4) move mouse to bring up unlock dialog on new head 5) unplug monitor 6) quickly hit keys on the keyboard

At this point gnome-screensaver will either crash, or show a black screen. If it shows a black screen then hitting "alt-f2" and then typing "pkill -f gnome-screensaver" will bring you to the session.

Red Hat

Affected Software

6 affected components
Gnome screensaver=2.20.0
Gnome screensaver=2.13
Gnome screensaver<=2.28.1
Gnome screensaver=2.20
Gnome screensaver=2.28.0
Gnome screensaver=2.26.1

Event History

Feb 5, 2010
Data Sourced
via Red Hat·04:19 PM
DescriptionSeverityAffected Software
Feb 8, 2010
CVE Published
via Red Hat·12:00 AM
Data Sourced
via Red Hat·12:00 AM
Remedy
Feb 11, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:30 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2010-0414?

CVE-2010-0414 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to sensitive information.

2

How do I fix CVE-2010-0414?

To fix CVE-2010-0414, you should upgrade the GNOME screensaver to version 2.28.2 or later where the vulnerability has been addressed.

3

Who is affected by CVE-2010-0414?

CVE-2010-0414 affects users of GNOME screensaver versions prior to 2.28.2, including versions 2.20.0, 2.20, 2.28.0, and 2.26.1.

4

What are the consequences of CVE-2010-0414?

The consequences of CVE-2010-0414 include the potential for physical attackers to bypass the screen lock and gain access to unattended workstations.

5

Is there a workaround for CVE-2010-0414?

Currently, there are no known workarounds for CVE-2010-0414, and upgrading to the latest version is the recommended solution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203