CVE-2017-8288
published 2017-04-27CVE-2017-8288: gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these…
PriorityP346high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
2.96%
85.8th percentile
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnome-shell | < gnome-shell 3.22.3-3 (bookworm) | gnome-shell 3.22.3-3 (bookworm) |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | >= 0 < 3.22.3-3 | 3.22.3-3 |
| gnome | gnome-shell | >= 0 < 3.22.3-3 | 3.22.3-3 |
| gnome | gnome-shell | >= 0 < 3.22.3-3 | 3.22.3-3 |
| gnome | gnome-shell | >= 0 < 3.22.3-3 | 3.22.3-3 |
| gnome | gnome-shell | >= 0 < 3.18.5-0ubuntu0.3+esm1 | 3.18.5-0ubuntu0.3+esm1 |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNOME Shell vulnerabilities
vendor_ubuntu·2024-10-03·CVSS 8.1
CVE-2017-8288 [HIGH] GNOME Shell vulnerabilities
Title: GNOME Shell vulnerabilities
Summary: Several security issues were fixed in GNOME Shell.
It was discovered that GNOME Shell mishandled extensions that fail to
reload, possibly leading to extensions staying enabled on the lock screen.
An attacker could possibly use this issue to launch applications, view
sensitive information, or execute arbitrary commands. (CVE-2017-8288)
It was discovered that the GNOME Shell incorrectly handled certain
keyboard inputs. An attacker could possibly use this issue to invoke
keyboard shortcuts, and potentially other actions while the workstation
was locked. (CVE-2019-3820)
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
gnome-shell: Mishandling extensions that fail to reload
vendor_redhat·2017-04-25·CVSS 8.1
CVE-2017-8288 [HIGH] CWE-248 gnome-shell: Mishandling extensions that fail to reload
gnome-shell: Mishandling extensions that fail to reload
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.
Package: gnome-shell (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2017-8288: gnome-shell - gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which...
vendor_debian·2017·CVSS 8.1
CVE-2017-8288 [HIGH] CVE-2017-8288: gnome-shell - gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which...
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.
Scope: local
bookworm: resolved (fixed in 3.22.3-3)
bullseye: resolved (fixed in 3.22.3-3)
forky: resolved (fixed in 3.22.3-3)
sid: resolved (fixed in 3.22.3-3)
trixie: resolved (fixed in 3.22.3-3)
OSV
gnome-shell vulnerabilities
osv·2024-10-03·CVSS 8.1
CVE-2017-8288 [HIGH] gnome-shell vulnerabilities
gnome-shell vulnerabilities
It was discovered that GNOME Shell mishandled extensions that fail to
reload, possibly leading to extensions staying enabled on the lock screen.
An attacker could possibly use this issue to launch applications, view
sensitive information, or execute arbitrary commands. (CVE-2017-8288)
It was discovered that the GNOME Shell incorrectly handled certain
keyboard inputs. An attacker could possibly use this issue to invoke
keyboard shortcuts, and potentially other actions while the workstation
was locked. (CVE-2019-3820)
GHSA
GHSA-rqjp-x4m8-wvwq: gnome-shell 3
ghsa_unreviewed·2022-05-17
CVE-2017-8288 [HIGH] CWE-20 GHSA-rqjp-x4m8-wvwq: gnome-shell 3
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.
OSV
CVE-2017-8288: gnome-shell 3
osv·2017-04-27·CVSS 8.1
CVE-2017-8288 [HIGH] CVE-2017-8288: gnome-shell 3
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-8288 gnome-shell: Mishandling extensions that fail to reload [fedora-all]
bugzilla·2017-04-27·CVSS 8.1
CVE-2017-8288 [HIGH] CVE-2017-8288 gnome-shell: Mishandling extensions that fail to reload [fedora-all]
CVE-2017-8288 gnome-shell: Mishandling extensions that fail to reload [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2017-8288 gnome-shell: Mishandling extensions that fail to reload
bugzilla·2017-04-27·CVSS 8.1
CVE-2017-8288 [HIGH] CVE-2017-8288 gnome-shell: Mishandling extensions that fail to reload
CVE-2017-8288 gnome-shell: Mishandling extensions that fail to reload
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.
Upstream patch:
https://github.com/GNOME/gnome-shell/commit/ff425d1db7082e2755d2a405af53861552acf2a1
Discussion:
Created gnome-shell tracking bugs for this issue:
Affects: fedora-all [bug 1446091]
---
Reference
http://www.securityfocus.com/bid/98070https://bugs.kali.org/view.php?id=2513https://bugzilla.gnome.org/show_bug.cgi?id=781728https://github.com/EasyScreenCast/EasyScreenCast/issues/46https://github.com/GNOME/gnome-shell/commit/ff425d1db7082e2755d2a405af53861552acf2a1http://www.securityfocus.com/bid/98070https://bugs.kali.org/view.php?id=2513https://bugzilla.gnome.org/show_bug.cgi?id=781728https://github.com/EasyScreenCast/EasyScreenCast/issues/46https://github.com/GNOME/gnome-shell/commit/ff425d1db7082e2755d2a405af53861552acf2a1
2017-04-27
Published