Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switching to the lock screen, which allows physically proximate attackers to bypass the lock screen by (1) leveraging a machine that had text selected when locking or (2) resuming from a suspension.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2014-08-07 04:13
Updated : 2017-09-07 18:29
NVD link : CVE-2014-5195
Mitre link : CVE-2014-5195
JSON object : View
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Products Affected
canonical
- ubuntu_linux
ayatana_project
- unity