CVE-2014-1949
published 2015-01-16CVE-2014-1949: GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock…
PriorityP431high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.33%
25.2th percentile
GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu | — | — |
| debian | cinnamon | < cinnamon 2.2.14-1 (bookworm) | cinnamon 2.2.14-1 (bookworm) |
| debian | gtk+2.0 | < cinnamon 2.2.14-1 (bookworm) | cinnamon 2.2.14-1 (bookworm) |
| debian | gtk+3.0 | < cinnamon 2.2.14-1 (bookworm) | cinnamon 2.2.14-1 (bookworm) |
| gnome | gtk | <= 3.10.9 | — |
| linuxmint | linux_mint | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-38gw-6g45-69p7: GTK+ 3
ghsa_unreviewed·2022-05-17
CVE-2014-1949 [HIGH] CWE-284 GHSA-38gw-6g45-69p7: GTK+ 3
GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.
OSV
CVE-2014-1949: GTK+ 3
osv·2015-01-16·CVSS 7.2
CVE-2014-1949 [HIGH] CVE-2014-1949: GTK+ 3
GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.
Debian
CVE-2014-1949: cinnamon - GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and...
vendor_debian·2014·CVSS 7.2
CVE-2014-1949 [HIGH] CVE-2014-1949: cinnamon - GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and...
GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.
Scope: local
bookworm: resolved (fixed in 2.2.14-1)
bullseye: resolved (fixed in 2.2.14-1)
forky: resolved (fixed in 2.2.14-1)
sid: resolved (fixed in 2.2.14-1)
trixie: resolved (fixed in 2.2.14-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1949 cinnamon: bypass screensaver lock via the keyboard's Menu key
bugzilla·2014-02-13·CVSS 7.2
CVE-2014-1949 [HIGH] CVE-2014-1949 cinnamon: bypass screensaver lock via the keyboard's Menu key
CVE-2014-1949 cinnamon: bypass screensaver lock via the keyboard's Menu key
Clemens Fries reported that, when using Cinnamon, it was possible to bypass the screensaver lock:
http://seclists.org/oss-sec/2014/q1/327
An attacker with physical access to the machine could use this flaw to take over the locked desktop session.
A patch is currently not yet available.
Discussion:
Created cinnamon tracking bugs for this issue:
Affects: fedora-all [bug 1064697]
---
Note that a similar issue was reported [1], which causes cinnamon to freeze when holding the 'menu' key. The original patch fixed this issue for the 'super' key (aka windows key) but the issue pertains for the menu key. Patch at [2] solves this issue.
A full explanation can be found at [3].
[1] https://github.com/linuxmint/Cinn
Bugzilla
CVE-2014-1949 cinnamon: bypass screensaver lock via the keyboard's Menu key [fedora-all]
bugzilla·2014-02-13·CVSS 7.2
CVE-2014-1949 [HIGH] CVE-2014-1949 cinnamon: bypass screensaver lock via the keyboard's Menu key [fedora-all]
CVE-2014-1949 cinnamon: bypass screensaver lock via the keyboard's Menu key [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
http://advisories.mageia.org/MGASA-2014-0374.htmlhttp://seclists.org/oss-sec/2014/q1/327http://seclists.org/oss-sec/2014/q1/331http://www.mandriva.com/security/advisories?name=MDVSA-2015:162http://www.ubuntu.com/usn/USN-2475-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759145https://bugzilla.redhat.com/show_bug.cgi?id=1064695https://github.com/linuxmint/cinnamon-screensaver/issues/44http://advisories.mageia.org/MGASA-2014-0374.htmlhttp://seclists.org/oss-sec/2014/q1/327http://seclists.org/oss-sec/2014/q1/331http://www.mandriva.com/security/advisories?name=MDVSA-2015:162http://www.ubuntu.com/usn/USN-2475-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759145https://bugzilla.redhat.com/show_bug.cgi?id=1064695https://github.com/linuxmint/cinnamon-screensaver/issues/44
2015-01-16
Published