LWN.net Logo

lxsession: arbitrary code execution

Package(s):lxsession CVE #(s):CVE-2010-2532
Created:July 23, 2010 Updated:August 2, 2010
Description: From the openSUSE advisory:

lxsession-logout did not properly lock the screen before suspending, hibernating and switching between users which could allow attackers with physical access to take control of the system to obtain sensitive information and / or execute arbitrary code in the context of the user who is currently logged in.

Alerts:
SUSE SUSE-SR:2010:014 2010-08-02
openSUSE openSUSE-SU-2010:0426-1 2010-07-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds