CVE-2019-3820
published 2019-02-06CVE-2019-3820: It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to…
PriorityP415medium4.3CVSS 3.1
AVPACLPRNUINSUCLILAL
EPSS
0.50%
39.8th percentile
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | gnome-shell | < gnome-shell 3.30.2-3 (bookworm) | gnome-shell 3.30.2-3 (bookworm) |
| gnome | gnome-shell | >= 0 < 3.30.2-3 | 3.30.2-3 |
| gnome | gnome-shell | >= 0 < 3.30.2-3 | 3.30.2-3 |
| gnome | gnome-shell | >= 0 < 3.30.2-3 | 3.30.2-3 |
| gnome | gnome-shell | >= 0 < 3.30.2-3 | 3.30.2-3 |
| gnome | gnome-shell | >= 0 < 3.18.5-0ubuntu0.3+esm1 | 3.18.5-0ubuntu0.3+esm1 |
| gnome | gnome-shell | >= 3.15.91 < 3.30.3 | 3.30.3 |
| gnome | gnome-shell | >= 3.31.0 < 3.31.5 | 3.31.5 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| the_gnome_project | gnome-shell | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv3.04.8MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_ubuntu8.1HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNOME Shell vulnerabilities
vendor_ubuntu·2024-10-03·CVSS 8.1
CVE-2017-8288 [HIGH] GNOME Shell vulnerabilities
Title: GNOME Shell vulnerabilities
Summary: Several security issues were fixed in GNOME Shell.
It was discovered that GNOME Shell mishandled extensions that fail to
reload, possibly leading to extensions staying enabled on the lock screen.
An attacker could possibly use this issue to launch applications, view
sensitive information, or execute arbitrary commands. (CVE-2017-8288)
It was discovered that the GNOME Shell incorrectly handled certain
keyboard inputs. An attacker could possibly use this issue to invoke
keyboard shortcuts, and potentially other actions while the workstation
was locked. (CVE-2019-3820)
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Ubuntu
GNOME Shell vulnerability
vendor_ubuntu·2019-05-06
CVE-2019-3820 GNOME Shell vulnerability
Title: GNOME Shell vulnerability
Summary: GNOME Shell could be made to execute keyboard shortcuts and other actions
while the workstation was locked.
It was discovered that the GNOME Shell incorrectly handled certain keyboard inputs.
An attacker could possibly use this issue to invoke keyboard shortcuts, and potentially
other actions while the workstation was locked.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
gnome-shell: partial lock screen bypass
vendor_redhat·2019-02-05·CVSS 4.3
CVE-2019-3820 [MEDIUM] CWE-285 gnome-shell: partial lock screen bypass
gnome-shell: partial lock screen bypass
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
A vulnerability was found where the gnome-shell lock screen, since version 3.15.91, does not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts and potentially other actions. This vulnerability was fixed in gnome-shell 3.31.5 and 3.30.3.
Debian
CVE-2019-3820: gnome-shell - It was discovered that the gnome-shell lock screen since version 3.15.91 did not...
vendor_debian·2019·CVSS 4.3
CVE-2019-3820 [MEDIUM] CVE-2019-3820: gnome-shell - It was discovered that the gnome-shell lock screen since version 3.15.91 did not...
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
Scope: local
bookworm: resolved (fixed in 3.30.2-3)
bullseye: resolved (fixed in 3.30.2-3)
forky: resolved (fixed in 3.30.2-3)
sid: resolved (fixed in 3.30.2-3)
trixie: resolved (fixed in 3.30.2-3)
OSV
gnome-shell vulnerabilities
osv·2024-10-03·CVSS 8.1
CVE-2017-8288 [HIGH] gnome-shell vulnerabilities
gnome-shell vulnerabilities
It was discovered that GNOME Shell mishandled extensions that fail to
reload, possibly leading to extensions staying enabled on the lock screen.
An attacker could possibly use this issue to launch applications, view
sensitive information, or execute arbitrary commands. (CVE-2017-8288)
It was discovered that the GNOME Shell incorrectly handled certain
keyboard inputs. An attacker could possibly use this issue to invoke
keyboard shortcuts, and potentially other actions while the workstation
was locked. (CVE-2019-3820)
GHSA
GHSA-jh4v-7q79-jf56: It was discovered that the gnome-shell lock screen since version 3
ghsa_unreviewed·2022-05-13
CVE-2019-3820 [MEDIUM] CWE-287 GHSA-jh4v-7q79-jf56: It was discovered that the gnome-shell lock screen since version 3
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
OSV
CVE-2019-3820: It was discovered that the gnome-shell lock screen since version 3
osv·2019-02-06·CVSS 4.3
CVE-2019-3820 [MEDIUM] CVE-2019-3820: It was discovered that the gnome-shell lock screen since version 3
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3820 gnome-shell: partial lock screen bypass [fedora-all]
bugzilla·2019-02-06·CVSS 4.3
CVE-2019-3820 [MEDIUM] CVE-2019-3820 gnome-shell: partial lock screen bypass [fedora-all]
CVE-2019-3820 gnome-shell: partial lock screen bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2019-3820 gnome-shell: partial lock screen bypass
bugzilla·2019-01-25·CVSS 4.3
CVE-2019-3820 [MEDIUM] CVE-2019-3820 gnome-shell: partial lock screen bypass
CVE-2019-3820 gnome-shell: partial lock screen bypass
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
This issue was introduced with the following ticket & commit:
https://bugzilla.gnome.org/show_bug.cgi?id=745039
https://gitlab.gnome.org/GNOME/gnome-shell/commit/c79d24b60e773262091023feb6ee1b3deef1c471
Upstream issue:
https://gitlab.gnome.org/GNOME/gnome-shell/issues/851
Discussion:
External References:
https://gitlab.gnome.org/GNOME/gnome-shell/issues/851
---
Created gnome-shell tracking bugs for this issue:
Affects: fedora-all [bug 1672815]
---
Acknowledgments:
Name: Ray S
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00049.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3820https://gitlab.gnome.org/GNOME/gnome-shell/issues/851https://usn.ubuntu.com/3966-1/http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00049.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3820https://gitlab.gnome.org/GNOME/gnome-shell/issues/851https://usn.ubuntu.com/3966-1/
2019-02-06
Published