Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by right-clicking on the indicator bar and then pressing the ALT and F2 keys.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2014/04/29/2 | mailing list |
http://www.securityfocus.com/bid/67117 | vdb entry |
http://www.openwall.com/lists/oss-security/2014/05/03/1 | mailing list |
https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1313885 | exploit |
http://ubuntu.com/usn/usn-2184-1 | vendor advisory |