PT-2014-3290 · Gnome · Gnome Shell
Published
2014-04-29
·
Updated
2014-04-29
·
CVE-2013-7221
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GNOME Shell versions prior to 3.10
Description
The issue concerns the automatic screen lock functionality in GNOME Shell, which fails to prevent access to the "Enter a Command" dialog. This allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation.
Recommendations
For versions prior to 3.10, consider disabling the automatic screen lock functionality or implementing an alternative security measure to prevent unauthorized access to the workstation until a fixed version is available. As a temporary workaround, ensure workstations are attended at all times or implement physical security measures to prevent unauthorized physical access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnome Shell