CVE-2010-2532: High severity suse linux vulnerability

Published Jul 14, 2010
·
Updated

DISPUTED lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other platforms, does not lock the screen when the Suspend or Hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, behavior in some threat environments.

Other sources

A bug report [1] for OpenSUSE indicates that lxsession-logout does not lock the screen before suspending, hibernating, or switching users. A patch [2] was attached to the bug to correct the issue.

This issue would affect lxsession in Fedora.

[1] https://bugzilla.novell.com/showbug.cgi?id=622083 [2] https://bugzillafiles.novell.org/attachment.cgi?id=375737

Red Hat

Affected Software

1 affected component
openSUSE openSUSE=11.3

Event History

Jul 14, 2010
Data Sourced
via Red Hat·08:59 PM
DescriptionSeverityAffected Software
Sep 3, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Disputed
08:00 PM

Frequently Asked Questions

1

What is the severity of CVE-2010-2532?

CVE-2010-2532 is classified as a low severity vulnerability.

2

How does CVE-2010-2532 affect users?

CVE-2010-2532 allows physically proximate attackers to access unattended laptops when the screen is not locked after Suspend or Hibernate.

3

Which platforms are affected by CVE-2010-2532?

CVE-2010-2532 primarily affects SUSE openSUSE 11.3 and potentially other platforms using LXDE.

4

How can I mitigate CVE-2010-2532?

To mitigate CVE-2010-2532, users should manually lock the screen before suspending or hibernating their devices.

5

Is there a patch available for CVE-2010-2532?

There is no specific patch for CVE-2010-2532, but updating to a later version of the operating system may resolve the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203