---
title: "CVE-2009-4996\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2009-4996?format=md
keywords: index, follow
---

# CVE-2009-4996

Publication date 7 September 2010

Last updated 4 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or
hibernate button is pressed, which might make it easier for physically
proximate attackers to access an unattended laptop via a resume action, a
related issue to CVE-2010-2532. NOTE: there is no general agreement that
this is a vulnerability, because separate control over locking can be an
equally secure, or more secure, behavior in some threat environments

[Read the notes from the security team](https://ubuntu.com/security/CVE-2009-4996?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| xfce4-session | 12.04 LTS precise | Ignored |
| 11.10 oneiric | Ignored |
| 11.04 natty | Ignored |
| 10.10 maverick | Ignored end of life |
| 10.04 LTS lucid | Ignored |
| 9.10 karmic | Ignored end of life |
| 9.04 jaunty | Ignored end of life |
| 8.04 LTS hardy | Ignored end of life |
| 6.06 LTS dapper | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

upstream does not intend to fix this in xfce4-session, but
rather via whatever power manager is installed.

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4996)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2009-4996)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2009-4996)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2009-4996)

### Other references

* <https://bugzilla.xfce.org/show_bug.cgi?id=4805>
* <https://www.cve.org/CVERecord?id=CVE-2009-4996>
