Vulnerability Name: | CVE-2013-2190 (CCN-88284) | ||||||||||||||||||||||||
Assigned: | 2013-07-01 | ||||||||||||||||||||||||
Published: | 2013-07-01 | ||||||||||||||||||||||||
Updated: | 2018-10-30 | ||||||||||||||||||||||||
Summary: | The translate_hierarchy_event function in x11/clutter-device-manager-xi2.c in Clutter, when resuming the system, does not properly handle XIQueryDevice errors when a device has "disappeared," which causes the gnome-shell to crash and allows physically proximate attackers to access the previous gnome-shell session via unspecified vectors. | ||||||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-2190 Source: SUSE Type: Vendor Advisory openSUSE-SU-2013:1540 Source: MLIST Type: UNKNOWN [oss-security] 20130618 Re: CVE request: gnome-shell crash, screen unlock on resume Source: CCN Type: BID-60593 gnome-shell '_gdk_x11_display_error_event()' Function Local Security Bypass Vulnerability Source: CONFIRM Type: UNKNOWN https://bugzilla.gnome.org/show_bug.cgi?id=701974 Source: CCN Type: Red Hat Bugzilla Bug 980111 (CVE-2013-2190) CVE-2013-2190 clutter: Improper translation of hierarchy events (gnome-shell crash after system resume) Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=980111 Source: XF Type: UNKNOWN clutter-translate-cve20132190-info-disc(88284) Source: CCN Type: Clutter GIT Repository Clutter Source: CONFIRM Type: Exploit, Patch https://git.gnome.org/browse/clutter/commit/?h=clutter-1.14&id=e310c68d7b38d521e341f4e8a36f54303079d74e Source: CONFIRM Type: UNKNOWN https://git.gnome.org/browse/clutter/commit/?h=clutter-1.16&id=d343cc6289583a7b0d929b82b740499ed588b1ab Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-2190 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |