| Vulnerability Name: | CVE-2014-3203 (CCN-93066) | ||||||||||||
| Assigned: | 2014-04-17 | ||||||||||||
| Published: | 2014-04-17 | ||||||||||||
| Updated: | 2014-05-07 | ||||||||||||
| Summary: | Unity before 7.2.1, as used in Ubuntu 14.04, does not properly restrict access to the Dash when the lock screen is active, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by pressing the SUPER key before the screen auto-locks. | ||||||||||||
| CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||
| CVSS v2 Severity: | 4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P) 3.2 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2014-3203 Source: UBUNTU Type: Vendor Advisory USN-2184-1 Source: MLIST Type: UNKNOWN [oss-security] 20140429 Re: Ubuntu 14.04: security problem in the lock screen Source: MLIST Type: UNKNOWN [oss-security] 20140503 Re: Ubuntu 14.04: security problem in the lock screen Source: CCN Type: OSVDB ID: 106422 Ubuntu Unity Screen Lock Dash Display Information Disclosure Source: CCN Type: BID-67116 Ubuntu 'Unity' Package Local Security Bypass Vulnerability Source: CCN Type: Ubuntu Bug #1308850 Dash is visible on top of the lockscreen after screen monitor auto locks Source: CONFIRM Type: Exploit https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1308850 Source: XF Type: UNKNOWN ubuntu-cve20143203-info-disc(93066) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||