| Vulnerability Name: | CVE-2014-3204 (CCN-92956) | ||||||||||||
| Assigned: | 2014-04-28 | ||||||||||||
| Published: | 2014-04-28 | ||||||||||||
| Updated: | 2014-05-07 | ||||||||||||
| Summary: | Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by right-clicking on the indicator bar and then pressing the ALT and F2 keys. | ||||||||||||
| CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||
| CVSS v2 Severity: | 4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P) 3.2 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2014-3204 Source: UBUNTU Type: Vendor Advisory USN-2184-1 Source: MLIST Type: UNKNOWN [oss-security] 20140429 Re: Ubuntu 14.04: security problem in the lock screen Source: MLIST Type: UNKNOWN [oss-security] 20140503 Re: Ubuntu 14.04: security problem in the lock screen Source: CCN Type: OSVDB ID: 106424 Ubuntu Unity Crafted Keyboard Shortcut Screen Lock Bypass Source: BID Type: UNKNOWN 67117 Source: CCN Type: BID-67117 Ubuntu 'Unity' Package Local Security Bypass Vulnerability Source: CCN Type: Ubuntu Bug #1313885 lock screen bypass Source: CONFIRM Type: Exploit https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1313885 Source: XF Type: UNKNOWN ubuntu-cve20143204-sec-bypass(92956) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||