CVE-2014-7300
Last modified
CVE-2014-7300 is a vulnerability of currently unknown severity. GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Gnome-Shell | 3.14.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Hpc Node | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
References
- http://openwall.com/lists/oss-security/2014/09/29/17Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0535.htmlThird Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=737456Issue Tracking, Vendor Advisory
- http://openwall.com/lists/oss-security/2014/09/29/17Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0535.htmlThird Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=737456Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-7300?
How severe is CVE-2014-7300?
How do I fix CVE-2014-7300?
Are you affected by CVE-2014-7300?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
