CVE-2021-3567
published 2022-03-25CVE-2021-3567: A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.14%
63.3th percentile
A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulnerability is to system availability.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | caribou | < caribou 0.4.21-7.1 (bookworm) | caribou 0.4.21-7.1 (bookworm) |
| gnome | caribou | < 0.4.21 | 0.4.21 |
| gnome | caribou | >= 0 < 0.4.21-7.1 | 0.4.21-7.1 |
| gnome | caribou | >= 0 < 0.4.21-7.1 | 0.4.21-7.1 |
| gnome | caribou | >= 0 < 0.4.21-7.1 | 0.4.21-7.1 |
| gnome | caribou | >= 0 < 0.4.21-7.1 | 0.4.21-7.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
caribou: segfault on pressing ē since Xorg CVE-2020-25712 fix
vendor_redhat·2021-01-13·CVSS 7.8
CVE-2021-3567 [HIGH] CWE-787 caribou: segfault on pressing ē since Xorg CVE-2020-25712 fix
caribou: segfault on pressing ē since Xorg CVE-2020-25712 fix
A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulnerability is to system availability.
A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulnerability is to system availability.
Package: caribou (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2021-3567: caribou - A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attack...
vendor_debian·2021·CVSS 7.8
CVE-2021-3567 [HIGH] CVE-2021-3567: caribou - A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attack...
A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 0.4.21-7.1)
bullseye: resolved (fixed in 0.4.21-7.1)
forky: resolved (fixed in 0.4.21-7.1)
sid: resolved (fixed in 0.4.21-7.1)
trixie: resolved (fixed in 0.4.21-7.1)
GHSA
GHSA-g7cf-5cjw-6ppm: A flaw was found in Caribou due to a regression of CVE-2020-25712 fix
ghsa_unreviewed·2022-03-26·CVSS 7.8
CVE-2021-3567 [HIGH] CWE-20 GHSA-g7cf-5cjw-6ppm: A flaw was found in Caribou due to a regression of CVE-2020-25712 fix
A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-3567: A flaw was found in Caribou due to a regression of CVE-2020-25712 fix
osv·2022-03-25·CVSS 7.8
CVE-2021-3567 [HIGH] CVE-2021-3567: A flaw was found in Caribou due to a regression of CVE-2020-25712 fix
A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-25
Published