CVE-2009-4642 describes a vulnerability in gnome-screensaver 2.26.1, where it incorrectly relies on the gnome-session D-Bus interface for idle time, even in Xfce environments like Xubuntu or Mythbuntu. This flaw allows a physically proximate attacker to bypass screen locking on unattended workstations. With a CVSS score of 7.2 (High), this vulnerability has a local attack vector with low complexity, enabling full compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.26.1CPE matchmatch criteria | cpe:2.3:a:gnome:screensaver:2.26.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.