CVE-2013-7220

GNOME Shell <3.8 - Command Injection

Title source: llm
STIX 2.1

Description

js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities search.

References (6)

Core 6
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1030431
Issue Tracking x_refsource_confirm
https://bugzilla.gnome.org/show_bug.cgi?id=686740
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/12/27/4
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/12/27/6
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/12/27/8

Scores

EPSS 0.0010
EPSS Percentile 26.5%

Details

Status published
Products (46)
gnome/gnome-shell 3.0.0
gnome/gnome-shell 3.0.0.1
gnome/gnome-shell 3.0.0.2
gnome/gnome-shell 3.0.1
gnome/gnome-shell 3.0.2
gnome/gnome-shell 3.1.3
gnome/gnome-shell 3.1.4
gnome/gnome-shell 3.1.90
gnome/gnome-shell 3.1.90.1
gnome/gnome-shell 3.1.91
... and 36 more
Published Apr 29, 2014
Tracked Since Feb 18, 2026