PT-2014-3289 · Gnome · Gnome Shell
Ratul Gupta
·
Publicado
2014-04-29
·
Atualizado
2014-04-29
·
CVE-2013-7220
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GNOME Shell (aka gnome-shell) versions prior to 3.8
Description
The issue allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities search field in the
js/ui/screenShield.js file.Recommendations
For versions prior to 3.8, consider disabling the screen shield functionality until a patch is available.
As a temporary workaround, restrict access to unattended workstations to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gnome Shell