CVE-2010-0414: High severity Gnome screensaver vulnerability
gnome-screensaver before 2.28.2 allows physically proximate attackers to bypass screen locking and access an unattended workstation by moving the mouse position to an external monitor and then disconnecting that monitor.
Other sources
Under certain circumstances it is possible to circumvent the security of screen locking functionality of gnome-screensaver by changing the systems physical monitor configuration.
Steps to reproduce:
1) Lock screen 2) Move mouse to removable monitor 3) hit escape key to cancel unlock dialog 4) move mouse to bring up unlock dialog on new head 5) unplug monitor 6) quickly hit keys on the keyboard
At this point gnome-screensaver will either crash, or show a black screen. If it shows a black screen then hitting "alt-f2" and then typing "pkill -f gnome-screensaver" will bring you to the session.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0414?
CVE-2010-0414 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2010-0414?
To fix CVE-2010-0414, you should upgrade the GNOME screensaver to version 2.28.2 or later where the vulnerability has been addressed.
Who is affected by CVE-2010-0414?
CVE-2010-0414 affects users of GNOME screensaver versions prior to 2.28.2, including versions 2.20.0, 2.20, 2.28.0, and 2.26.1.
What are the consequences of CVE-2010-0414?
The consequences of CVE-2010-0414 include the potential for physical attackers to bypass the screen lock and gain access to unattended workstations.
Is there a workaround for CVE-2010-0414?
Currently, there are no known workarounds for CVE-2010-0414, and upgrading to the latest version is the recommended solution.