First published: Wed Jul 14 2010(Updated: )
** DISPUTED ** lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other platforms, does not lock the screen when the Suspend or Hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, behavior in some threat environments.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE | =11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2532 is classified as a low severity vulnerability.
CVE-2010-2532 allows physically proximate attackers to access unattended laptops when the screen is not locked after Suspend or Hibernate.
CVE-2010-2532 primarily affects SUSE openSUSE 11.3 and potentially other platforms using LXDE.
To mitigate CVE-2010-2532, users should manually lock the screen before suspending or hibernating their devices.
There is no specific patch for CVE-2010-2532, but updating to a later version of the operating system may resolve the issue.