CVE-2015-1319
published 2015-09-17CVE-2015-1319: The Unity Settings Daemon before 14.04.0+14.04.20150825-0ubuntu2 and 15.04.x before 15.04.1+15.04.20150408-0ubuntu1.2 does not properly detect if the screen is…
PriorityP49low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.36%
29.2th percentile
The Unity Settings Daemon before 14.04.0+14.04.20150825-0ubuntu2 and 15.04.x before 15.04.1+15.04.20150408-0ubuntu1.2 does not properly detect if the screen is locked, which allows physically proximate attackers to mount removable media while the screen is locked as demonstrated by inserting a USB thumb drive.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v9qw-3gh7-4hvj: The Unity Settings Daemon before 14
ghsa_unreviewed·2022-05-14
CVE-2015-1319 [LOW] CWE-20 GHSA-v9qw-3gh7-4hvj: The Unity Settings Daemon before 14
The Unity Settings Daemon before 14.04.0+14.04.20150825-0ubuntu2 and 15.04.x before 15.04.1+15.04.20150408-0ubuntu1.2 does not properly detect if the screen is locked, which allows physically proximate attackers to mount removable media while the screen is locked as demonstrated by inserting a USB thumb drive.
OSV
CVE-2015-1319: The Unity Settings Daemon before 14
osv·2015-04-03·CVSS 2.1
CVE-2015-1319 [LOW] CVE-2015-1319: The Unity Settings Daemon before 14
The Unity Settings Daemon before 14.04.0+14.04.20150825-0ubuntu2 and 15.04.x before 15.04.1+15.04.20150408-0ubuntu1.2 does not properly detect if the screen is locked, which allows physically proximate attackers to mount removable media while the screen is locked as demonstrated by inserting a USB thumb drive.
Ubuntu
Unity Settings Daemon vulnerability
vendor_ubuntu·2015-09-16
CVE-2015-1319 Unity Settings Daemon vulnerability
Title: Unity Settings Daemon vulnerability
Summary: Unity Settings Daemon would allow mounting removable media while the screen
is locked.
It was discovered that the Unity Settings Daemon incorrectly allowed
removable media to be mounted when the screen is locked. If a vulnerability
were discovered in some other desktop component, such as an image library,
a local attacker could possibly use this issue to gain access to the
session.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-17
Published