CVE-2015-3213 – clutter: screenlock bypass by performing certain mouse gestures
https://notcve.org/view.php?id=CVE-2015-3213
The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via certain (1) mouse or (2) touch gestures. Vulnerabilidad en el código de manejo de gestos en Clutter en versiones anteriores a 1.16.2, permite a atacantes físicamente próximos eludir la pantalla de bloqueo a través de ciertos gestos de (1) ratón o (2) táctiles. A flaw was found in the way clutter processed certain mouse and touch gestures. An attacker could use this flaw to bypass the screen lock. • http://rhn.redhat.com/errata/RHSA-2015-1510.html https://bugzilla.gnome.org/show_bug.cgi?id=710227 https://bugzilla.gnome.org/show_bug.cgi?id=749847 https://bugzilla.redhat.com/show_bug.cgi?id=1227098 https://git.gnome.org/browse/clutter/commit/?h=clutter-1.18&id=97724939c8de004d7fa230f3ff64862d957f93a9 https://access.redhat.com/security/cve/CVE-2015-3213 • CWE-284: Improper Access Control CWE-305: Authentication Bypass by Primary Weakness •
CVE-2013-2190
https://notcve.org/view.php?id=CVE-2013-2190
The translate_hierarchy_event function in x11/clutter-device-manager-xi2.c in Clutter, when resuming the system, does not properly handle XIQueryDevice errors when a device has "disappeared," which causes the gnome-shell to crash and allows physically proximate attackers to access the previous gnome-shell session via unspecified vectors. La función translate_hierarchy_event de x11/clutter-device-manager-xi2.c en nClutter, al reanudar el sistema, no maneja adecuadamente los errores XIQueryDevice cuando un dispositivo ha "desaparecido," lo que provoca el cuelgue de gnome-shell y permite físicamente a atacantes próximos el acceso a anteriores sesiones de gnome-shell a través de vectores sin especificar. • http://lists.opensuse.org/opensuse-updates/2013-10/msg00014.html http://www.openwall.com/lists/oss-security/2013/06/19/1 https://bugzilla.gnome.org/show_bug.cgi?id=701974 https://bugzilla.redhat.com/show_bug.cgi?id=980111 https://git.gnome.org/browse/clutter/commit/?h=clutter-1.14&id=e310c68d7b38d521e341f4e8a36f54303079d74e https://git.gnome.org/browse/clutter/commit/?h=clutter-1.16&id=d343cc6289583a7b0d929b82b740499ed588b1ab • CWE-264: Permissions, Privileges, and Access Controls •