Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 496166 (CVE-2013-7220) - gnome-base/gnome-shell-3.7.92: blind command execution via activities search keyboard focus (CVE-2013-7220)
Summary: gnome-base/gnome-shell-3.7.92: blind command execution via activities search ...
Status: RESOLVED FIXED
Alias: CVE-2013-7220
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-12-27 14:11 UTC by Agostino Sarubbo
Modified: 2014-06-29 20:59 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-12-27 14:11:36 UTC
From ${URL} :

1. gnome-shell: blind command execution via activities search keyboard focus
The issue is that in Fedora 18, when you open either the Activities
panel or "Enter a command" dialog box (Alt+F2), and then lock the screen
or let the screensaver lock the screen, then if you start typing on the
lock screen, instead of entering the password or just waking the screen,
it actually types anything you type on the Activities panel or "Enter a
command" dialog box, so anyone who enters a executable command and press
enter, the command is executed even when the screen is locked.

https://bugzilla.gnome.org/show_bug.cgi?id=686740

And a series of commits fix this issue via:

https://git.gnome.org/browse/gnome-shell/log/js/ui/screenShield.js?qt=grep&q=686740

This issue was addressed in upstream release of gnome-shell-3.7.92


@maintainer(s): since the fixed version is already stable, please remove the affected versions from the tree.@Security: please vote and/or file the request for the GLSA.
Comment 1 Pacho Ramos gentoo-dev 2013-12-27 20:52:09 UTC
Affected versions cleaned
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2014-06-19 01:25:24 UTC
GLSA Vote: No
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2014-06-19 01:27:46 UTC
CVE-2013-7220 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-7220):
  js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows
  physically proximate attackers to execute arbitrary commands by leveraging
  an unattended workstation with the keyboard focus on the Activities search.
Comment 4 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2014-06-29 20:59:20 UTC
GLSA vote: no.

Closing as [noglsa]