CVE-2014-7300

Description

GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.

Risk Information

Base Score
8.4
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.044

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2015:0535) Low: GNOME Shell security, bug fix, and enhancement update cogl-1.14.0-6.el7.i686.rpmLinux
(RHSA-2015:0535) Low: GNOME Shell security, bug fix, and enhancement update cogl-1.14.0-6.el7.x86_64.rpmLinux
(RHSA-2015:0535) Low: GNOME Shell security, bug fix, and enhancement update cogl-devel-1.14.0-6.el7.i686.rpmLinux
(RHSA-2015:0535) Low: GNOME Shell security, bug fix, and enhancement update cogl-devel-1.14.0-6.el7.x86_64.rpmLinux
(RHSA-2015:0535) Low: GNOME Shell security, bug fix, and enhancement update cogl-doc-1.14.0-6.el7.noarch.rpmLinux
(RHSA-2015:0535) Low: GNOME Shell security, bug fix, and enhancement update gnome-shell-3.8.4-45.el7.x86_64.rpmLinux
(RHSA-2015:0535) Low: GNOME Shell security, bug fix, and enhancement update gnome-shell-browser-plugin-3.8.4-45.el7.x86_64.rpmLinux
(RHSA-2015:0535) Low: GNOME Shell security, bug fix, and enhancement update mutter-3.8.4-16.el7.i686.rpmLinux
(RHSA-2015:0535) Low: GNOME Shell security, bug fix, and enhancement update mutter-3.8.4-16.el7.x86_64.rpmLinux
(RHSA-2015:0535) Low: GNOME Shell security, bug fix, and enhancement update mutter-devel-3.8.4-16.el7.i686.rpmLinux
(RHSA-2015:0535) Low: GNOME Shell security, bug fix, and enhancement update mutter-devel-3.8.4-16.el7.x86_64.rpmLinux
SUSE-SU-2015:0515-1(SUSE Linux Enterprise Desktop 12 ) gnome-settings-daemon-3.10.2-20.1.x86_64.rpmLinux
SUSE-SU-2015:0515-1(SUSE Linux Enterprise Desktop 12 ) gnome-settings-daemon-debuginfo-3.10.2-20.1.x86_64.rpmLinux
SUSE-SU-2015:0515-1(SUSE Linux Enterprise Desktop 12 ) gnome-settings-daemon-debugsource-3.10.2-20.1.x86_64.rpmLinux
SUSE-SU-2015:0515-1(SUSE Linux Enterprise Desktop 12 ) gnome-settings-daemon-lang-3.10.2-20.1.noarch.rpmLinux
(RHSA-2015:0535)Low: Shell security, bug fix, and enhancement update clutter-1.14.4-12.el7.i686.rpmLinux
(RHSA-2015:0535)Low: Shell security, bug fix, and enhancement update clutter-1.14.4-12.el7.x86_64.rpmLinux
(RHSA-2015:0535)Low: Shell security, bug fix, and enhancement update clutter-debuginfo-1.14.4-12.el7.i686.rpmLinux
(RHSA-2015:0535)Low: Shell security, bug fix, and enhancement update clutter-debuginfo-1.14.4-12.el7.x86_64.rpmLinux
(RHSA-2015:0535)Low: Shell security, bug fix, and enhancement update clutter-devel-1.14.4-12.el7.i686.rpmLinux
(RHSA-2015:0535)Low: Shell security, bug fix, and enhancement update clutter-devel-1.14.4-12.el7.x86_64.rpmLinux
(RHSA-2015:0535)Low: Shell security, bug fix, and enhancement update clutter-doc-1.14.4-12.el7.x86_64.rpmLinux
(RHSA-2015:0535)Low: Shell security, bug fix, and enhancement update cogl-debuginfo-1.14.0-6.el7.i686.rpmLinux
(RHSA-2015:0535)Low: Shell security, bug fix, and enhancement update cogl-debuginfo-1.14.0-6.el7.x86_64.rpmLinux
(RHSA-2015:0535)Low: Shell security, bug fix, and enhancement update gnome-shell-debuginfo-3.8.4-45.el7.x86_64.rpmLinux
(RHSA-2015:0535)Low: Shell security, bug fix, and enhancement update mutter-debuginfo-3.8.4-16.el7.i686.rpmLinux
(RHSA-2015:0535)Low: Shell security, bug fix, and enhancement update mutter-debuginfo-3.8.4-16.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234