Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-3203


Unity before 7.2.1, as used in Ubuntu 14.04, does not properly restrict access to the Dash when the lock screen is active, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by pressing the SUPER key before the screen auto-locks.


Published

2014-05-06T14:55:06.090

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.4 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ayatana_project unity ≤ 7.2.0 Yes
Application ayatana_project unity 7.0.0 Yes
Application ayatana_project unity 7.0.1 Yes
Application ayatana_project unity 7.1.0 Yes
Application ayatana_project unity 7.1.1 Yes
Application ayatana_project unity 7.1.2 Yes
Application ayatana_project unity 7.1.3 Yes
Operating System canonical ubuntu_linux 14.04 Yes

References