Ubuntu update for gnome-shell



Published: 2023-09-21
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2023-43090
CWE-ID CWE-264
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
Ubuntu
Operating systems & Components / Operating system

gnome-shell (Ubuntu package)
Operating systems & Components / Operating system package or component

Vendor Canonical Ltd.

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU81043

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-43090

CWE-ID:

Exploit availability:

Description

The vulnerability allows an attacker to gain access to sensitive information.

The vulnerability exists due to certain key combinations remain active when the user session is locked. An attacker with physical access to device can activate the "single window mode" and "video" buttons in GNOME Screenshot utility by pressing twice the "V" then once the "W" key and record screen or make screenshots.

Mitigation

Update the affected package gnome-shell to the latest version.

Vulnerable software versions

Ubuntu: 23.04

gnome-shell (Ubuntu package): before 44.3-0ubuntu1.1

Fixed software versions

CPE2.3 External links

http://ubuntu.com/security/notices/USN-6395-1


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?



###SIDEBAR###