PT-2014-3290 · Gnome · Gnome Shell
Publicado
2014-04-29
·
Atualizado
2014-04-29
·
CVE-2013-7221
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GNOME Shell versions prior to 3.10
Description
The issue concerns the automatic screen lock functionality in GNOME Shell, which fails to prevent access to the "Enter a Command" dialog. This allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation.
Recommendations
For versions prior to 3.10, consider disabling the automatic screen lock functionality or implementing an alternative security measure to prevent unauthorized access to the workstation until a fixed version is available. As a temporary workaround, ensure workstations are attended at all times or implement physical security measures to prevent unauthorized physical access.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gnome Shell