fkie_cve-2013-7220
Vulnerability from fkie_nvd
Published
2014-04-29 14:38
Modified
2025-04-12 10:46
Severity ?
Summary
js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities search.



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "F2C74C9F-D2CC-4636-87DD-630FD2F74DDE",
              "versionEndIncluding": "3.7.92",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.0.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "82ACC9E5-5CFF-4B0D-9E6C-A08FE8575822",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.0.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "114459B1-D495-48A9-9AE2-FBCB4286F193",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.0.0.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "F606D55F-BFB3-4618-AC95-5AD3BD903B66",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "F459BAF6-E5AA-4B37-B9D9-8FB583418956",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.0.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "F58A7204-B850-4789-8970-109A5DAD12F2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "CA4ABEC4-FE7F-46A9-A8E9-3EA6ECF3C387",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "F9656B63-4658-4CC8-B1F1-18B4256A3CAC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.90:*:*:*:*:*:*:*",
              "matchCriteriaId": "661C01B1-0ABF-43DD-9593-94E13A4A464A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.90.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "F924115B-B5A2-41E9-A48C-14D501C740F8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.91:*:*:*:*:*:*:*",
              "matchCriteriaId": "2C4E1E27-8B5B-409D-A617-81F028BBB720",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.91.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "2788E003-3514-47E4-837F-3D13D0D48420",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.92:*:*:*:*:*:*:*",
              "matchCriteriaId": "C5741472-28E5-4F45-8029-FB275D82DF73",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.2.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "86BF5692-BE0D-4209-A56E-7ACD49067B9E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "FC9AE668-71FC-4023-A898-0C2AF6C82856",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.2.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "51DCD82C-64C8-44E7-A352-1F782B17B5E4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.2.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "68DE0BDF-56E9-47FF-9455-0D076F21BBED",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.3.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "6350AB8C-190A-4CCD-BBD1-16E9EE8A6550",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.3.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "42D44580-FFEB-41A3-8CF5-8E7F2C876355",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.3.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "7433A0F4-60D1-4144-80CE-CAC8C7CAA0DF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.3.90:*:*:*:*:*:*:*",
              "matchCriteriaId": "0A6FEE79-012C-46E6-9038-71B0A5C58119",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.3.91:*:*:*:*:*:*:*",
              "matchCriteriaId": "87526D65-2C71-4F49-9616-BEDFEBA85308",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.3.92:*:*:*:*:*:*:*",
              "matchCriteriaId": "302C4D31-5FC8-4418-8CD2-8A55853ADCDD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.4.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "EEF9CB49-8832-4A7D-BC9C-36F813941490",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.4.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "85C39341-601F-434E-96B9-011864C5AE76",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.4.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "ADD78C76-5804-45F7-AB05-06AFA826FC26",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.5.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "CBB3B460-C89E-48C8-81FE-B50FF87AF3A9",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.5.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "A5381CBC-786E-475B-B2C2-73E4B8A86E8C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.5.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "21D11F9C-30EC-41F0-BEC1-F2391BD431C0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.5.90:*:*:*:*:*:*:*",
              "matchCriteriaId": "AD82EFDE-9845-429F-8525-D26332445D7F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.5.91:*:*:*:*:*:*:*",
              "matchCriteriaId": "63F6D77A-ED01-4E1B-BAE5-E9CA21B697EA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.5.92:*:*:*:*:*:*:*",
              "matchCriteriaId": "395C11EB-B102-406B-90C7-B644C42EB100",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.6.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "4FF5BBD5-0818-4211-B6A8-9796D299435B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.6.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "C1273739-1D54-4E09-8C11-E6A15D7F5DC5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.6.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "486233D1-DEF4-4A48-8F3E-6AD049754258",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.6.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "1A0D5581-3930-4EC1-87FB-D4FF77200476",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.6.3.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "0C216CB4-EC05-49C3-8FC9-3E3CC5B76130",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "C0BEE3CC-9F94-452E-B564-F291CC5F50CF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "BC2F084D-CAC4-4CC2-8B01-A2CA8D5C249E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "435020D6-9881-4F54-AB67-ABA146219C75",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "F7DC4858-6A22-4086-BD8F-D78C69A9B9C3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.3.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "27968FC8-9122-4FFE-ABFE-A453507DA335",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "0A719995-DE52-4A91-A4FC-DADFFE5B1DC0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.4.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "947957CD-1381-41BD-B156-DFEEC6D5B86F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "66C15C16-975D-494B-A4C8-F732A87E6081",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.91:*:*:*:*:*:*:*",
              "matchCriteriaId": "794CB61C-B23D-44CB-9845-F9A372793E5F",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities search."
    },
    {
      "lang": "es",
      "value": "js/ui/screenShield.js en GNOME Shell (tambi\u00e9n conocido como gnome-shell) anterior a 3.8 permite a atacantes f\u00edsicamente pr\u00f3ximos ejecutar comandos arbitrarios mediante el aprovechamiento de una estaci\u00f3n de trabajo desatendida con el foco de teclado en el campo de b\u00fasqueda de Activities."
    }
  ],
  "evaluatorComment": "Per: https://cwe.mitre.org/data/definitions/77.html\n\n\"CWE-77: Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)\"",
  "id": "CVE-2013-7220",
  "lastModified": "2025-04-12T10:46:40.837",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "MEDIUM",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "LOCAL",
          "authentication": "NONE",
          "availabilityImpact": "PARTIAL",
          "baseScore": 4.6,
          "confidentialityImpact": "PARTIAL",
          "integrityImpact": "PARTIAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "version": "2.0"
        },
        "exploitabilityScore": 3.9,
        "impactScore": 6.4,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ]
  },
  "published": "2014-04-29T14:38:46.967",
  "references": [
    {
      "source": "cve@mitre.org",
      "url": "http://www.openwall.com/lists/oss-security/2013/12/27/4"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.openwall.com/lists/oss-security/2013/12/27/6"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.openwall.com/lists/oss-security/2013/12/27/8"
    },
    {
      "source": "cve@mitre.org",
      "url": "https://bugzilla.gnome.org/show_bug.cgi?id=686740"
    },
    {
      "source": "cve@mitre.org",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1030431"
    },
    {
      "source": "cve@mitre.org",
      "url": "https://github.com/o2platform/DefCon_RESTing/tree/master/Live-Demos/Neo4j"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.openwall.com/lists/oss-security/2013/12/27/4"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.openwall.com/lists/oss-security/2013/12/27/6"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.openwall.com/lists/oss-security/2013/12/27/8"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://bugzilla.gnome.org/show_bug.cgi?id=686740"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1030431"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://github.com/o2platform/DefCon_RESTing/tree/master/Live-Demos/Neo4j"
    }
  ],
  "sourceIdentifier": "cve@mitre.org",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…