CVE-2014-7300
published 2014-12-25CVE-2014-7300: GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which…
PriorityP335high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.47%
38.2th percentile
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnome-shell | < gnome-shell 3.14.1-1 (bookworm) | gnome-shell 3.14.1-1 (bookworm) |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | >= 0 < 3.14.1-1 | 3.14.1-1 |
| gnome | gnome-shell | >= 0 < 3.14.1-1 | 3.14.1-1 |
| gnome | gnome-shell | >= 0 < 3.14.1-1 | 3.14.1-1 |
| gnome | gnome-shell | >= 0 < 3.14.1-1 | 3.14.1-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gnome-shell: lockscreen bypass with printscreen key
vendor_redhat·2014-09-27·CVSS 7.2
CVE-2014-7300 [HIGH] CWE-285 gnome-shell: lockscreen bypass with printscreen key
gnome-shell: lockscreen bypass with printscreen key
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.
It was found that the Gnome shell did not disable the Print Screen key when the screen was locked. This could allow an attacker with physical access to a system with a locked screen to crash the screen-locking application by creating a large amount of screenshots.
Debian
CVE-2014-7300: gnome-shell - GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not...
vendor_debian·2014·CVSS 7.2
CVE-2014-7300 [HIGH] CVE-2014-7300: gnome-shell - GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not...
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.
Scope: local
bookworm: resolved (fixed in 3.14.1-1)
bullseye: resolved (fixed in 3.14.1-1)
forky: resolved (fixed in 3.14.1-1)
sid: resolved (fixed in 3.14.1-1)
trixie: resolved (fixed in 3.14.1-1)
GHSA
GHSA-gg6w-rmxx-j7xr: GNOME Shell 3
ghsa_unreviewed·2022-05-17
CVE-2014-7300 [HIGH] GHSA-gg6w-rmxx-j7xr: GNOME Shell 3
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.
OSV
CVE-2014-7300: GNOME Shell 3
osv·2014-12-25·CVSS 7.2
CVE-2014-7300 [HIGH] CVE-2014-7300: GNOME Shell 3
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7300 gnome-shell: lockscreen bypass with printscreen key [rhel-7.1]
bugzilla·2014-10-17·CVSS 7.2
CVE-2014-7300 [HIGH] CVE-2014-7300 gnome-shell: lockscreen bypass with printscreen key [rhel-7.1]
CVE-2014-7300 gnome-shell: lockscreen bypass with printscreen key [rhel-7.1]
+++ This bug was initially created as a clone of Bug #1147917 +++
It was discovered [1] that PrtSc key is not disabled when the screen is locked.
Taking a bunch of screenshots at once bloats gnome-shell to the point
where it's pretty easy to get it targeted by the kernel's oom-killer.
This means that anyone with access to the keyboard of a locked GNOME
session can (briefly) disable the lockscreen, which lets them see and
interact with the running gnome session.
This might be fixed in gnome-shell 3.14.1, some patches available in the original bugreport [1].
[1]: https://bugzilla.gnome.org/show_bug.cgi?id=737456
--- Additional comment from Murray McAllister on 2014-10-02 22:17:43 EDT ---
Created gnome-shell
Bugzilla
CVE-2014-7300 gnome-shell: lockscreen bypass with printscreen key
bugzilla·2014-09-30·CVSS 7.2
CVE-2014-7300 [HIGH] CVE-2014-7300 gnome-shell: lockscreen bypass with printscreen key
CVE-2014-7300 gnome-shell: lockscreen bypass with printscreen key
It was discovered [1] that PrtSc key is not disabled when the screen is locked.
Taking a bunch of screenshots at once bloats gnome-shell to the point
where it's pretty easy to get it targeted by the kernel's oom-killer.
This means that anyone with access to the keyboard of a locked GNOME
session can (briefly) disable the lockscreen, which lets them see and
interact with the running gnome session.
This might be fixed in gnome-shell 3.14.1, some patches available in the original bugreport [1].
[1]: https://bugzilla.gnome.org/show_bug.cgi?id=737456
Discussion:
Created gnome-shell tracking bugs for this issue:
Affects: fedora-all [bug 1149039]
---
CVE-2014-7300 was assigned for:
"PrtSc is an unauthenticated request tha
http://openwall.com/lists/oss-security/2014/09/29/17http://rhn.redhat.com/errata/RHSA-2015-0535.htmlhttps://bugzilla.gnome.org/show_bug.cgi?id=737456https://git.gnome.org/browse/gnome-shell/commit/?id=a72dca361080ffc9f45ff90188a7cf013c3c4013https://git.gnome.org/browse/gnome-shell/commit/?id=f02b007337e61436aaa0e81a86ad707b6d277378http://openwall.com/lists/oss-security/2014/09/29/17http://rhn.redhat.com/errata/RHSA-2015-0535.htmlhttps://bugzilla.gnome.org/show_bug.cgi?id=737456https://git.gnome.org/browse/gnome-shell/commit/?id=a72dca361080ffc9f45ff90188a7cf013c3c4013https://git.gnome.org/browse/gnome-shell/commit/?id=f02b007337e61436aaa0e81a86ad707b6d277378
2014-12-25
Published