PT-2019-16738 · Gnome+7 · Gnome Shell+7

Doran Moppert

·

Publicado

2019-02-05

·

Atualizado

2024-10-03

·

CVE-2019-3820

CVSS v3.1

4.8

Média

VetorAV:P/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions gnome-shell versions 3.15.91 and later
Description The gnome-shell lock screen does not properly restrict all contextual actions, allowing an attacker with physical access to a locked workstation to invoke certain keyboard shortcuts and potentially other actions.
Recommendations For gnome-shell versions 3.15.91 and later, consider disabling the lock screen feature until a patch is available to prevent potential exploitation. Restrict physical access to workstations to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2019:3553
ALT-PU-2019-1455
CESA-2019_3553
CESA-2020_1021
CVE-2019-3820
ELSA-2020-1021
OESA-2021-1403
OPENSUSE-SU-2019:1582-1
OPENSUSE-SU-2019_1529-1
OPENSUSE-SU-2019_1582-1
OPENSUSE-SU-2024:10797-1
RHSA-2019:3553
RHSA-2019_3553
RHSA-2020:1021
RHSA-2020_1021
RLSA-2019:3553
RLSA-2019_3553
SUSE-SU-2019:1390-1
SUSE-SU-2019:1459-1
SUSE-SU-2019_1390-1
SUSE-SU-2019_1459-1
USN-3966-1
USN-7052-1

Produtos afetados

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Gnome Shell