Security restrictions bypass in gnome-shell - CVE-2019-3820

 

Security restrictions bypass in gnome-shell - CVE-2019-3820

Published: February 14, 2019


Vulnerability identifier: #VU17709
CSH Severity: Medium
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3820
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a physical attacker to bypass security restrictions on the system.

The vulnerability exists due to the lock screen feature does not properly restrict all contextual actions. A physical attacker can click on the password text field to bypass the lock screen and re-enable certain keyboard shortcuts, which the attacker can use to perform unauthorized actions on the system.


Affected software

gnome-shell
Arch Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
CentOS
Opensuse
Ubuntu
openEuler
gnome-shell (Ubuntu package)
accountsservice (Red Hat package)
LibRaw (Red Hat package)
libcanberra (Red Hat package)
colord (Red Hat package)
shared-mime-info (Red Hat package)
tracker (Red Hat package)
xchat (Red Hat package)
gtk3 (Red Hat package)
nautilus (Red Hat package)
gsettings-desktop-schemas (Red Hat package)
control-center (Red Hat package)
gnome-tweak-tool (Red Hat package)
gnome-settings-daemon (Red Hat package)
gnome-shell-extensions (Red Hat package)
gnome-online-accounts (Red Hat package)
libgweather (Red Hat package)
gdm (Red Hat package)
mutter (Red Hat package)
gnome-shell (Red Hat package)
gnome-shell
gnome-shell-debugsource
gnome-shell-debuginfo
gnome-shell-help
osinfo-db (Red Hat package)
Data Computing Appliance (DCA)

How to mitigate CVE-2019-3820

Update to version 3.31.90.

gnome-shell - update to 3.31.90
gnome-shell (Ubuntu package) - addressed in versions Ubuntu Pro, 3.28.3+git20190124-0ubuntu18.04.2, 3.30.2-0ubuntu1.18.10.2
accountsservice (Red Hat package) - update to 0.6.50-7.el7
LibRaw (Red Hat package) - update to 0.19.4-1.el7
libcanberra (Red Hat package) - update to 0.30-9.el7
colord (Red Hat package) - update to 1.3.4-2.el7
shared-mime-info (Red Hat package) - update to 1.8-5.el7
tracker (Red Hat package) - update to 1.10.5-8.el7
xchat (Red Hat package) - update to 2.8.8-25.el7
gtk3 (Red Hat package) - update to 3.22.30-5.el7
nautilus (Red Hat package) - update to 3.26.3.1-7.el7
gsettings-desktop-schemas (Red Hat package) - update to 3.28.0-3.el7
control-center (Red Hat package) - update to 3.28.1-6.el7
gnome-tweak-tool (Red Hat package) - update to 3.28.1-7.el7
gnome-settings-daemon (Red Hat package) - update to 3.28.1-8.el7
gnome-shell-extensions (Red Hat package) - update to 3.28.1-11.el7
gnome-online-accounts (Red Hat package) - update to 3.28.2-1.el7
libgweather (Red Hat package) - update to 3.28.2-3.el7
gdm (Red Hat package) - update to 3.28.2-22.el7
mutter (Red Hat package) - update to 3.28.3-20.el7
gnome-shell (Red Hat package) - update to 3.28.3-24.el7
gnome-shell - update to 3.30.1-10
gnome-shell-debugsource - update to 3.30.1-10
gnome-shell-debuginfo - update to 3.30.1-10
gnome-shell-help - update to 3.30.1-10
Data Computing Appliance (DCA) - update to 4.3.0.0
osinfo-db (Red Hat package) - update to 20190805-2.el7

External References

Related Security Bulletins