CVE-2010-2532: High severity suse linux vulnerability
DISPUTED lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other platforms, does not lock the screen when the Suspend or Hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, behavior in some threat environments.
Other sources
A bug report [1] for OpenSUSE indicates that lxsession-logout does not lock the screen before suspending, hibernating, or switching users. A patch [2] was attached to the bug to correct the issue.
This issue would affect lxsession in Fedora.
[1] https://bugzilla.novell.com/showbug.cgi?id=622083 [2] https://bugzillafiles.novell.org/attachment.cgi?id=375737
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2532?
CVE-2010-2532 is classified as a low severity vulnerability.
How does CVE-2010-2532 affect users?
CVE-2010-2532 allows physically proximate attackers to access unattended laptops when the screen is not locked after Suspend or Hibernate.
Which platforms are affected by CVE-2010-2532?
CVE-2010-2532 primarily affects SUSE openSUSE 11.3 and potentially other platforms using LXDE.
How can I mitigate CVE-2010-2532?
To mitigate CVE-2010-2532, users should manually lock the screen before suspending or hibernating their devices.
Is there a patch available for CVE-2010-2532?
There is no specific patch for CVE-2010-2532, but updating to a later version of the operating system may resolve the issue.