CVE-2014-3203

Unity < 7.2.1 - Unauthenticated Lock Screen Bypass via Dash Access

Title source: llm
STIX 2.1

Description

Unity before 7.2.1, as used in Ubuntu 14.04, does not properly restrict access to the Dash when the lock screen is active, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by pressing the SUPER key before the screen auto-locks.

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/04/29/2
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/05/03/1
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://ubuntu.com/usn/usn-2184-1

Scores

EPSS 0.0051
EPSS Percentile 40.4%

Details

CWE
CWE-264
Status published
Products (8)
ayatana_project/unity 7.0.0
ayatana_project/unity 7.0.1
ayatana_project/unity 7.1.0
ayatana_project/unity 7.1.1
ayatana_project/unity 7.1.2
ayatana_project/unity 7.1.3
ayatana_project/unity < 7.2.0
canonical/ubuntu_linux 14.04
Published May 06, 2014
Tracked Since Feb 18, 2026