---
title: "CVE-2009-4642\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2009-4642?format=md
keywords: index, follow
---

# CVE-2009-4642

Publication date 11 February 2010

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

gnome-screensaver 2.26.1 relies on the gnome-session D-Bus interface to
determine session idle time, even when an Xfce desktop such as Xubuntu or
Mythbuntu is used, which allows physically proximate attackers to access an
unattended workstation on which screen locking had been intended.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2009-4642?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| gnome-screensaver | 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 9.10 karmic | Not affected |
| 9.04 jaunty | Not affected |
| 8.10 intrepid | Not affected |
| 8.04 LTS hardy | Not affected |
| 6.06 LTS dapper | Not affected |
| xfce4-session | 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 9.10 karmic | Ignored end of life |
| 9.04 jaunty | Ignored end of life |
| 8.10 intrepid | Ignored end of life, was needed |
| 8.04 LTS hardy | Ignored end of life |
| 6.06 LTS dapper | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [kees](https://launchpad.net/~kees)

While it looks like a gnome-screensaver bug, for stable releases,
this is an issue primarily for xfce, which doesn't use g-ss correctly.
Going forward, gnome-session has been added to the g-ss package deps
so that the issue is more obvious to integration attempts of g-ss.

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4642)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2009-4642)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2009-4642)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2009-4642)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2009-4642>
