fkie_cve-2013-7221
Vulnerability from fkie_nvd
Published
2014-04-29 14:38
Modified
2025-04-12 10:46
Severity ?
Summary
The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation.
Impacted products



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "DE87665B-BD50-4EC7-852E-C33775D57DA7",
              "versionEndIncluding": "3.9.92",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.0.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "82ACC9E5-5CFF-4B0D-9E6C-A08FE8575822",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.0.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "114459B1-D495-48A9-9AE2-FBCB4286F193",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.0.0.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "F606D55F-BFB3-4618-AC95-5AD3BD903B66",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "F459BAF6-E5AA-4B37-B9D9-8FB583418956",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.0.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "F58A7204-B850-4789-8970-109A5DAD12F2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "CA4ABEC4-FE7F-46A9-A8E9-3EA6ECF3C387",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "F9656B63-4658-4CC8-B1F1-18B4256A3CAC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.90:*:*:*:*:*:*:*",
              "matchCriteriaId": "661C01B1-0ABF-43DD-9593-94E13A4A464A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.90.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "F924115B-B5A2-41E9-A48C-14D501C740F8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.91:*:*:*:*:*:*:*",
              "matchCriteriaId": "2C4E1E27-8B5B-409D-A617-81F028BBB720",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.91.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "2788E003-3514-47E4-837F-3D13D0D48420",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.1.92:*:*:*:*:*:*:*",
              "matchCriteriaId": "C5741472-28E5-4F45-8029-FB275D82DF73",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.2.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "86BF5692-BE0D-4209-A56E-7ACD49067B9E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "FC9AE668-71FC-4023-A898-0C2AF6C82856",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.2.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "51DCD82C-64C8-44E7-A352-1F782B17B5E4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.2.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "68DE0BDF-56E9-47FF-9455-0D076F21BBED",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.3.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "6350AB8C-190A-4CCD-BBD1-16E9EE8A6550",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.3.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "42D44580-FFEB-41A3-8CF5-8E7F2C876355",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.3.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "7433A0F4-60D1-4144-80CE-CAC8C7CAA0DF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.3.90:*:*:*:*:*:*:*",
              "matchCriteriaId": "0A6FEE79-012C-46E6-9038-71B0A5C58119",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.3.91:*:*:*:*:*:*:*",
              "matchCriteriaId": "87526D65-2C71-4F49-9616-BEDFEBA85308",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.3.92:*:*:*:*:*:*:*",
              "matchCriteriaId": "302C4D31-5FC8-4418-8CD2-8A55853ADCDD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.4.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "EEF9CB49-8832-4A7D-BC9C-36F813941490",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.4.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "85C39341-601F-434E-96B9-011864C5AE76",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.4.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "ADD78C76-5804-45F7-AB05-06AFA826FC26",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.5.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "CBB3B460-C89E-48C8-81FE-B50FF87AF3A9",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.5.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "A5381CBC-786E-475B-B2C2-73E4B8A86E8C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.5.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "21D11F9C-30EC-41F0-BEC1-F2391BD431C0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.5.90:*:*:*:*:*:*:*",
              "matchCriteriaId": "AD82EFDE-9845-429F-8525-D26332445D7F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.5.91:*:*:*:*:*:*:*",
              "matchCriteriaId": "63F6D77A-ED01-4E1B-BAE5-E9CA21B697EA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.5.92:*:*:*:*:*:*:*",
              "matchCriteriaId": "395C11EB-B102-406B-90C7-B644C42EB100",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.6.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "4FF5BBD5-0818-4211-B6A8-9796D299435B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.6.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "C1273739-1D54-4E09-8C11-E6A15D7F5DC5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.6.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "486233D1-DEF4-4A48-8F3E-6AD049754258",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.6.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "1A0D5581-3930-4EC1-87FB-D4FF77200476",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.6.3.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "0C216CB4-EC05-49C3-8FC9-3E3CC5B76130",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "C0BEE3CC-9F94-452E-B564-F291CC5F50CF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "BC2F084D-CAC4-4CC2-8B01-A2CA8D5C249E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "435020D6-9881-4F54-AB67-ABA146219C75",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "F7DC4858-6A22-4086-BD8F-D78C69A9B9C3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.3.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "27968FC8-9122-4FFE-ABFE-A453507DA335",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "0A719995-DE52-4A91-A4FC-DADFFE5B1DC0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.4.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "947957CD-1381-41BD-B156-DFEEC6D5B86F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "66C15C16-975D-494B-A4C8-F732A87E6081",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.91:*:*:*:*:*:*:*",
              "matchCriteriaId": "794CB61C-B23D-44CB-9845-F9A372793E5F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.7.92:*:*:*:*:*:*:*",
              "matchCriteriaId": "E8162075-30F7-461A-993B-7DEC08C3C72F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.8.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "A62FB546-C16E-45F1-8D1C-1178E20E46B1",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.8.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "E50C3387-4A78-4E82-848B-F27085846F38",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.8.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "5B0916E4-641F-45C7-98CE-C7927AAB15A2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.8.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "1B95357F-9DA7-4D12-92C2-0AB96CB40B38",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.8.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "867E7520-B75C-4B0F-9850-21CF47BD6023",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.8.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "3725C85F-EE88-4918-9ECF-5CF9AE3CFCEF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.9.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "B90A9B62-F9D1-4784-A141-E8255E239810",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.9.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "9DEC960F-FAB5-4F82-9985-E7A921970F12",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.9.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "CA69A4F4-8624-4305-BA89-D5950B0BFD7E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.9.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "DEA8284C-B916-403C-B953-2F77B771A06D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.9.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "BADEE65E-8766-41B0-A6E1-94FE62D11FEE",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.9.90:*:*:*:*:*:*:*",
              "matchCriteriaId": "D1C1915B-61BA-4DF9-BB15-A42632C7F5AB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:3.9.91:*:*:*:*:*:*:*",
              "matchCriteriaId": "DE79F30A-9534-4A4B-827F-6C6A1E65C6BA",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the \"Enter a Command\" dialog, which allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation."
    },
    {
      "lang": "es",
      "value": "La funcionalidad de bloqueo de pantalla autom\u00e1tico en GNOME Shell (tambi\u00e9n conocido como gnome-shell) anterior a 3.10 no previene acceso al dialogo \"Enter a Command\", lo que permite a atacantes f\u00edsicamente pr\u00f3ximos ejecutar comandos arbitrarios aprovechandose de una estaci\u00f3n de trabajo desatendida."
    }
  ],
  "id": "CVE-2013-7221",
  "lastModified": "2025-04-12T10:46:40.837",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "MEDIUM",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "LOCAL",
          "authentication": "NONE",
          "availabilityImpact": "PARTIAL",
          "baseScore": 4.6,
          "confidentialityImpact": "PARTIAL",
          "integrityImpact": "PARTIAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "version": "2.0"
        },
        "exploitabilityScore": 3.9,
        "impactScore": 6.4,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ]
  },
  "published": "2014-04-29T14:38:47.170",
  "references": [
    {
      "source": "cve@mitre.org",
      "url": "http://www.openwall.com/lists/oss-security/2013/12/27/4"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.openwall.com/lists/oss-security/2013/12/27/8"
    },
    {
      "source": "cve@mitre.org",
      "url": "https://bugzilla.gnome.org/show_bug.cgi?id=708313"
    },
    {
      "source": "cve@mitre.org",
      "url": "https://git.gnome.org/browse/gnome-shell/commit/js/ui/main.js?id=efdf1ff755943fba1f8a9aaeff77daa3ed338088"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.openwall.com/lists/oss-security/2013/12/27/4"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.openwall.com/lists/oss-security/2013/12/27/8"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://bugzilla.gnome.org/show_bug.cgi?id=708313"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://git.gnome.org/browse/gnome-shell/commit/js/ui/main.js?id=efdf1ff755943fba1f8a9aaeff77daa3ed338088"
    }
  ],
  "sourceIdentifier": "cve@mitre.org",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…