Bug 1046839 (CVE-2013-7221) - CVE-2013-7221 gnome-shell: run command dialog visible above screen locker
Summary: CVE-2013-7221 gnome-shell: run command dialog visible above screen locker
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2013-7221
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1030960
TreeView+ depends on / blocked
 
Reported: 2013-12-27 05:07 UTC by Huzaifa S. Sidhpurwala
Modified: 2019-09-29 13:11 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2013-12-28 02:46:36 UTC
Embargoed:


Attachments (Terms of Use)

Description Huzaifa S. Sidhpurwala 2013-12-27 05:07:26 UTC
In Fedora 19, the "Enter the Command" dialog box is visible even after you lock the screen, so anyone can write the commands in the box and execute them over a locked screen.

The issue is still to be fixed and tested on Gnome Fedora 18 and 19 machines. KDE version were not found to be affected.

This flaw is split from bug 1030431

Comment 1 Huzaifa S. Sidhpurwala 2013-12-27 05:23:55 UTC
Upstream bug: 
https://bugzilla.gnome.org/show_bug.cgi?id=708313

Upstream patch:
https://git.gnome.org/browse/gnome-shell/commit/js/ui/main.js?id=efdf1ff755943fba1f8a9aaeff77daa3ed338088

This issue has been addressed in gnome-shell-3.10.0

Comment 2 Huzaifa S. Sidhpurwala 2013-12-27 05:27:08 UTC
The patch for this issue was backported to Fedora-19 via the following commit:

http://pkgs.fedoraproject.org/cgit/gnome-shell.git/commit/?h=f19&id=dfe68f1744ae3235df60a0be7a900b9279c7f5db 

It is available by upgrading to gnome-shell-3.8.4-3.fc19

Fedora-20 ships gnome-shell-3.10.2 and therefore is not affected.

Comment 4 Huzaifa S. Sidhpurwala 2013-12-28 02:46:36 UTC
This issue has been assigned CVE-2013-7221 as per:

http://www.openwall.com/lists/oss-security/2013/12/27/8


Note You need to log in before you can comment on or make changes to this bug.