CVE-2010-2532

lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other platforms, does not lock the screen when the Suspend or Hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, behavior in some threat environments.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
opensuseopensuse
11.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lxsession
bookworm
0.5.5-2
fixed
bullseye
0.5.5-2
fixed
sid
0.5.5-3
fixed
trixie
0.5.5-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lxsession
trusty
not-affected
saucy
ignored
raring
ignored
quantal
ignored
precise
not-affected
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
karmic
ignored
jaunty
dne
hardy
dne
dapper
dne
Common Weakness Enumeration