cbcvebase.
CVE-2014-3204
published 2014-05-06

CVE-2014-3204: Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen…

medium4.4CVSS 3.1
AVLACMAuNCPIPAP
Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by right-clicking on the indicator bar and then pressing the ALT and F2 keys.

Affected

9 ranges
VendorProductVersion rangeFixed in
ayatana_projectunity<= 7.2.0
ayatana_projectunity
ayatana_projectunity
ayatana_projectunity
ayatana_projectunity
ayatana_projectunity
ayatana_projectunity
canonicalubuntu_linux
dellunity>= 0 < 7.2.0+14.04.20140423-0ubuntu1.17.2.0+14.04.20140423-0ubuntu1.1

CVSS provenance

nvd4.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM