PT-2014-3289 · Gnome · Gnome Shell
Ratul Gupta
·
Published
2014-04-29
·
Updated
2014-04-29
·
CVE-2013-7220
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GNOME Shell (aka gnome-shell) versions prior to 3.8
Description
The issue allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities search field in the
js/ui/screenShield.js file.Recommendations
For versions prior to 3.8, consider disabling the screen shield functionality until a patch is available.
As a temporary workaround, restrict access to unattended workstations to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gnome Shell