CVE-2013-7374
published 2014-05-01CVE-2013-7374: The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 does not properly restrict access to…
PriorityP418medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.38%
30.6th percentile
The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 does not properly restrict access to Evolution, which allows local users to bypass the greeter screen restrictions by clicking the date.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xc86-4263-5hwg: The Ubuntu Date and Time Indicator (aka indicator-datetime) 13
ghsa_unreviewed·2022-05-17
CVE-2013-7374 [MEDIUM] GHSA-xc86-4263-5hwg: The Ubuntu Date and Time Indicator (aka indicator-datetime) 13
The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 does not properly restrict access to Evolution, which allows local users to bypass the greeter screen restrictions by clicking the date.
OSV
CVE-2013-7374: The Ubuntu Date and Time Indicator (aka indicator-datetime) 13
osv·2014-04-30·CVSS 4.6
CVE-2013-7374 [MEDIUM] CVE-2013-7374: The Ubuntu Date and Time Indicator (aka indicator-datetime) 13
The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 does not properly restrict access to Evolution, which allows local users to bypass the greeter screen restrictions by clicking the date.
Ubuntu
Date and Time Indicator vulnerability
vendor_ubuntu·2014-04-30
CVE-2013-7374 Date and Time Indicator vulnerability
Title: Date and Time Indicator vulnerability
Summary: The Date and Time Indicator would allow unintended access.
It was discovered that the Date and Time Indicator incorrectly allowed
Evolution to be opened at the greeter screen. An attacker could use this
issue to possibly gain unexpected access to applications such as a web
browser with privileges of the greeter user.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bazaar.launchpad.net/~indicator-applet-developers/indicator-datetime/trunk.13.10/revision/282http://www.openwall.com/lists/oss-security/2014/04/29/3http://www.openwall.com/lists/oss-security/2014/04/30/1http://www.ubuntu.com/usn/USN-2186-1https://bugs.launchpad.net/ubuntu/%2Bsource/indicator-datetime/%2Bbug/1246812http://bazaar.launchpad.net/~indicator-applet-developers/indicator-datetime/trunk.13.10/revision/282http://www.openwall.com/lists/oss-security/2014/04/29/3http://www.openwall.com/lists/oss-security/2014/04/30/1http://www.ubuntu.com/usn/USN-2186-1https://bugs.launchpad.net/ubuntu/%2Bsource/indicator-datetime/%2Bbug/1246812
2014-05-01
Published