CVE-2009-4641
Summary
| CVE | CVE-2009-4641 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-02-11 21:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | gnome-screensaver 2.28.0 does not resume adherence to its activation settings after an inhibiting application becomes unavailable on the session bus, which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnome | Screensaver | 2.28.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Support / Security / Advisories / / MDVSA-2010:040 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| USN-866-1: gnome-screensaver vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Bug #411350 “gnome-screensaver not functioning” : Bugs : “gnome-screensaver” package : Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | launchpad.net | |
| Bug 600488 – Totem is leaking session inhibitors | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.gnome.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-03-17 | Vincent Danen | Not vulnerable. This issue did not affect the versions of gnome-screensaver as shipped with Red Hat Enterprise Linux 5. |
There are currently no legacy QID mappings associated with this CVE.