CVE-2014-7300

GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
gnomegnome-shell
3.14.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_hpc_node
7.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gnome-shell
bookworm
43.9-0+deb12u2
fixed
bookworm (security)
43.9-0+deb12u2
fixed
bullseye
3.38.6-1~deb11u2
fixed
bullseye (security)
3.38.6-1~deb11u2
fixed
sid
47.0-3
fixed
trixie
47.0-3
fixed
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnome-shell
artful
not-affected
bionic
not-affected
cosmic
not-affected
disco
not-affected
lucid
ignored
precise
ignored
trusty
dne
utopic
ignored
vivid
ignored
wily
ignored
xenial
not-affected
yakkety
not-affected
zesty
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
gnome-settings-daemon
suse enterprise desktop 15
3.26.2-6.12
fixed
suse enterprise desktop 15 SP1
3.26.2-6.12
fixed
suse enterprise desktop 15 SP4
41.0-150400.1.8
fixed
suse enterprise desktop 15 SP5
41.0-150500.2.1
fixed
suse enterprise desktop 15 SP6
45.1-150600.1.5
fixed
suse enterprise desktop 15 SP7
45.1-150700.7.3
fixed
suse enterprise sap 12
3.10.2-20.1
fixed
suse enterprise sap 12 SP5
3.20.1-50.16.1
fixed
suse enterprise sap 15
3.26.2-6.12
fixed
suse enterprise sap 15 SP1
3.26.2-6.12
fixed
suse enterprise sap 15 SP4
41.0-150400.1.8
fixed
suse enterprise sap 15 SP5
41.0-150500.2.1
fixed
suse enterprise sap 15 SP6
45.1-150600.1.5
fixed
suse enterprise sap 15 SP7
45.1-150700.7.3
fixed
suse enterprise server 12
3.10.2-20.1
fixed
suse enterprise server 12 SP2
3.20.1-40.5
fixed
suse enterprise server 12 SP5
3.20.1-50.16.1
fixed
suse enterprise server 15
3.26.2-6.12
fixed
suse enterprise server 15 SP1
3.26.2-6.12
fixed
suse enterprise server 15 SP4
41.0-150400.1.8
fixed
suse enterprise server 15 SP5
41.0-150500.2.1
fixed
suse enterprise server 15 SP6
45.1-150600.1.5
fixed
suse enterprise server 15 SP7
45.1-150700.7.3
fixed
gnome-settings-daemon-devel
suse enterprise desktop 15
3.26.2-6.12
fixed
suse enterprise desktop 15 SP1
3.26.2-6.12
fixed
suse enterprise desktop 15 SP4
41.0-150400.1.8
fixed
suse enterprise desktop 15 SP5
41.0-150500.2.1
fixed
suse enterprise desktop 15 SP6
45.1-150600.1.5
fixed
suse enterprise desktop 15 SP7
45.1-150700.7.3
fixed
suse enterprise sap 15
3.26.2-6.12
fixed
suse enterprise sap 15 SP1
3.26.2-6.12
fixed
suse enterprise sap 15 SP4
41.0-150400.1.8
fixed
suse enterprise sap 15 SP5
41.0-150500.2.1
fixed
suse enterprise sap 15 SP6
45.1-150600.1.5
fixed
suse enterprise sap 15 SP7
45.1-150700.7.3
fixed
suse enterprise server 15
3.26.2-6.12
fixed
suse enterprise server 15 SP1
3.26.2-6.12
fixed
suse enterprise server 15 SP4
41.0-150400.1.8
fixed
suse enterprise server 15 SP5
41.0-150500.2.1
fixed
suse enterprise server 15 SP6
45.1-150600.1.5
fixed
suse enterprise server 15 SP7
45.1-150700.7.3
fixed
gnome-settings-daemon-lang
suse enterprise desktop 15
3.26.2-6.12
fixed
suse enterprise desktop 15 SP1
3.26.2-6.12
fixed
suse enterprise desktop 15 SP4
41.0-150400.1.8
fixed
suse enterprise desktop 15 SP5
41.0-150500.2.1
fixed
suse enterprise desktop 15 SP6
45.1-150600.1.5
fixed
suse enterprise desktop 15 SP7
45.1-150700.7.3
fixed
suse enterprise sap 12
3.10.2-20.1
fixed
suse enterprise sap 12 SP5
3.20.1-50.16.1
fixed
suse enterprise sap 15
3.26.2-6.12
fixed
suse enterprise sap 15 SP1
3.26.2-6.12
fixed
suse enterprise sap 15 SP4
41.0-150400.1.8
fixed
suse enterprise sap 15 SP5
41.0-150500.2.1
fixed
suse enterprise sap 15 SP6
45.1-150600.1.5
fixed
suse enterprise sap 15 SP7
45.1-150700.7.3
fixed
suse enterprise server 12
3.10.2-20.1
fixed
suse enterprise server 12 SP2
3.20.1-40.5
fixed
suse enterprise server 12 SP5
3.20.1-50.16.1
fixed
suse enterprise server 15
3.26.2-6.12
fixed
suse enterprise server 15 SP1
3.26.2-6.12
fixed
suse enterprise server 15 SP4
41.0-150400.1.8
fixed
suse enterprise server 15 SP5
41.0-150500.2.1
fixed
suse enterprise server 15 SP6
45.1-150600.1.5
fixed
suse enterprise server 15 SP7
45.1-150700.7.3
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
clutter
RHEL 7
0:1.14.4-12.el7
fixed
clutter-devel
RHEL 7
0:1.14.4-12.el7
fixed
clutter-doc
RHEL 7
0:1.14.4-12.el7
fixed
cogl
RHEL 7
0:1.14.0-6.el7
fixed
cogl-devel
RHEL 7
0:1.14.0-6.el7
fixed
cogl-doc
RHEL 7
0:1.14.0-6.el7
fixed
gnome-shell
RHEL 7
0:3.8.4-45.el7
fixed
gnome-shell-browser-plugin
RHEL 7
0:3.8.4-45.el7
fixed
mutter
RHEL 7
0:3.8.4-16.el7
fixed
mutter-devel
RHEL 7
0:3.8.4-16.el7
fixed
Common Weakness Enumeration