PT-2017-18261 · Gnome+3 · Gnome Shell+3

Emilio Pozuelo Monfort

·

Published

2017-04-27

·

Updated

2024-10-03

·

CVE-2017-8288

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions gnome-shell versions 3.22 through 3.24.1
Description The issue arises from the mishandling of extensions that fail to reload, potentially leaving them enabled on the lock screen. This could allow a bystander to launch applications, although interaction with them would be restricted. Additionally, information from the extensions could be visible, such as open applications or music being played. In some cases, it might even be possible to execute arbitrary commands, depending on the extensions a user has enabled. The problem stems from a lack of exception handling in the js/ui/extensionSystem.js file.
Recommendations For gnome-shell versions 3.22 through 3.24.1, consider disabling extensions that could pose a risk until a proper fix is applied, especially those that could execute arbitrary commands or reveal sensitive information. As a temporary workaround, restrict access to the lock screen to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1596
CVE-2017-8288
MGASA-2018-0055
MGASA-2018-0057
OPENSUSE-SU-2024:10797-1
SUSE-SU-2017:2217-1
SUSE-SU-2017_2217-1
USN-7052-1

Affected Products

Alt Linux
Suse
Ubuntu
Gnome Shell