PT-2014-3290 · Gnome · Gnome Shell

Published

2014-04-29

·

Updated

2014-04-29

·

CVE-2013-7221

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNOME Shell versions prior to 3.10
Description The issue concerns the automatic screen lock functionality in GNOME Shell, which fails to prevent access to the "Enter a Command" dialog. This allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation.
Recommendations For versions prior to 3.10, consider disabling the automatic screen lock functionality or implementing an alternative security measure to prevent unauthorized access to the workstation until a fixed version is available. As a temporary workaround, ensure workstations are attended at all times or implement physical security measures to prevent unauthorized physical access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7221

Affected Products

Gnome Shell