PT-2017-18261 · Gnome+3 · Gnome Shell+3
Emilio Pozuelo Monfort
·
Published
2017-04-27
·
Updated
2024-10-03
·
CVE-2017-8288
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
gnome-shell versions 3.22 through 3.24.1
Description
The issue arises from the mishandling of extensions that fail to reload, potentially leaving them enabled on the lock screen. This could allow a bystander to launch applications, although interaction with them would be restricted. Additionally, information from the extensions could be visible, such as open applications or music being played. In some cases, it might even be possible to execute arbitrary commands, depending on the extensions a user has enabled. The problem stems from a lack of exception handling in the js/ui/extensionSystem.js file.
Recommendations
For gnome-shell versions 3.22 through 3.24.1, consider disabling extensions that could pose a risk until a proper fix is applied, especially those that could execute arbitrary commands or reveal sensitive information. As a temporary workaround, restrict access to the lock screen to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Ubuntu
Gnome Shell