CVE-2010-2532
openSUSE 11.3 - Unattended Laptop Access via Suspend/Hibernate Without Screen Lock
Title source: llmDescription
lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other platforms, does not lock the screen when the Suspend or Hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, behavior in some threat environments.
References (6)
Core 6
Core References
Various Sources
https://bugzillafiles.novell.org/attachment.cgi?id=375737
Issue Tracking
https://bugzilla.novell.com/show_bug.cgi?id=622083
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=614608
Mailing List mailing-list
http://www.openwall.com/lists/oss-security/2010/07/15/1
Mailing List vendor-advisory
http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
Mailing List mailing-list
http://www.openwall.com/lists/oss-security/2010/07/16/4
Scores
EPSS
0.0040
EPSS Percentile
32.5%
Details
CWE
CWE-264
Status
published
Products (1)
opensuse/opensuse
11.3
Published
Sep 03, 2010
Tracked Since
Feb 18, 2026