Security restrictions bypass in gnome-shell - CVE-2019-3820
Published: February 14, 2019
Vulnerability details
The vulnerability allows a physical attacker to bypass security restrictions on the system.
The vulnerability exists due to the lock screen feature does not properly restrict all contextual actions. A physical attacker can click on the password text field to bypass the lock screen and re-enable certain keyboard shortcuts, which the attacker can use to perform unauthorized actions on the system.
Affected software
Arch Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
CentOS
Opensuse
Ubuntu
openEuler
gnome-shell (Ubuntu package)
accountsservice (Red Hat package)
LibRaw (Red Hat package)
libcanberra (Red Hat package)
colord (Red Hat package)
shared-mime-info (Red Hat package)
tracker (Red Hat package)
xchat (Red Hat package)
gtk3 (Red Hat package)
nautilus (Red Hat package)
gsettings-desktop-schemas (Red Hat package)
control-center (Red Hat package)
gnome-tweak-tool (Red Hat package)
gnome-settings-daemon (Red Hat package)
gnome-shell-extensions (Red Hat package)
gnome-online-accounts (Red Hat package)
libgweather (Red Hat package)
gdm (Red Hat package)
mutter (Red Hat package)
gnome-shell (Red Hat package)
gnome-shell
gnome-shell-debugsource
gnome-shell-debuginfo
gnome-shell-help
osinfo-db (Red Hat package)
Data Computing Appliance (DCA)
How to mitigate CVE-2019-3820
gnome-shell (Ubuntu package) - addressed in versions Ubuntu Pro, 3.28.3+git20190124-0ubuntu18.04.2, 3.30.2-0ubuntu1.18.10.2
accountsservice (Red Hat package) - update to 0.6.50-7.el7
LibRaw (Red Hat package) - update to 0.19.4-1.el7
libcanberra (Red Hat package) - update to 0.30-9.el7
colord (Red Hat package) - update to 1.3.4-2.el7
shared-mime-info (Red Hat package) - update to 1.8-5.el7
tracker (Red Hat package) - update to 1.10.5-8.el7
xchat (Red Hat package) - update to 2.8.8-25.el7
gtk3 (Red Hat package) - update to 3.22.30-5.el7
nautilus (Red Hat package) - update to 3.26.3.1-7.el7
gsettings-desktop-schemas (Red Hat package) - update to 3.28.0-3.el7
control-center (Red Hat package) - update to 3.28.1-6.el7
gnome-tweak-tool (Red Hat package) - update to 3.28.1-7.el7
gnome-settings-daemon (Red Hat package) - update to 3.28.1-8.el7
gnome-shell-extensions (Red Hat package) - update to 3.28.1-11.el7
gnome-online-accounts (Red Hat package) - update to 3.28.2-1.el7
libgweather (Red Hat package) - update to 3.28.2-3.el7
gdm (Red Hat package) - update to 3.28.2-22.el7
mutter (Red Hat package) - update to 3.28.3-20.el7
gnome-shell (Red Hat package) - update to 3.28.3-24.el7
gnome-shell - update to 3.30.1-10
gnome-shell-debugsource - update to 3.30.1-10
gnome-shell-debuginfo - update to 3.30.1-10
gnome-shell-help - update to 3.30.1-10
Data Computing Appliance (DCA) - update to 4.3.0.0
osinfo-db (Red Hat package) - update to 20190805-2.el7
External References
Related Security Bulletins
- Security restrictions bypass in gnome-shell
- Arch Linux update for gdm
- Arch Linux update for gdm
- Ubuntu update for GNOME Shell
- OpenSUSE Linux update for gnome-shell
- OpenSUSE Linux update for gnome-shell
- CentOS 7 update for gnome-settings-daemon
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Red Hat Enterprise Linux 7 update for GNOME
- openEuler update for gnome-shell
- Ubuntu update for gnome-shell