CVE-2014-1949
Mandriva Linux Security Advisory 2015-162
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.
GTK+ 3.10.9 y anteriores, utilizado en cinnamon-screensaver, gnome-screensaver, y otras aplicaciones, permite a atacantes físicamente próximos evadir la pantalla de bloqueo mediante la activación del botón del menú.
Clemens Fries reported that, when using Cinnamon, it was possible to bypass the screensaver lock. An attacker with physical access to the machine could use this flaw to take over the locked desktop session. This was fixed by including a patch for the root cause of the issue in gtk+3.0, which came from the implementation of popup menus in GtkWindow. This update also includes other patches from upstream to fix bugs affecting GtkFileChooser and GtkSpinButton, and a crash related to clipboard handling.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-02-12 CVE Reserved
- 2015-01-16 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://advisories.mageia.org/MGASA-2014-0374.html | Third Party Advisory | |
http://seclists.org/oss-sec/2014/q1/327 | Mailing List |
|
http://seclists.org/oss-sec/2014/q1/331 | Mailing List |
|
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759145 | Third Party Advisory | |
https://bugzilla.redhat.com/show_bug.cgi?id=1064695 | Issue Tracking | |
https://github.com/linuxmint/cinnamon-screensaver/issues/44 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.mandriva.com/security/advisories?name=MDVSA-2015:162 | 2023-08-03 | |
http://www.ubuntu.com/usn/USN-2475-1 | 2023-08-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linuxmint Search vendor "Linuxmint" | Linux Mint Search vendor "Linuxmint" for product "Linux Mint" | 17.0 Search vendor "Linuxmint" for product "Linux Mint" and version "17.0" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Gtk Search vendor "Gnome" for product "Gtk" | <= 3.10.9 Search vendor "Gnome" for product "Gtk" and version " <= 3.10.9" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Search vendor "Canonical" for product "Ubuntu" | 14.04 Search vendor "Canonical" for product "Ubuntu" and version "14.04" | lts |
Affected
|