CVE-2013-7221: Medium severity Gnome gnome-shell vulnerability
The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7221?
CVE-2013-7221 is considered a medium severity vulnerability due to the potential for unauthorized command execution on an unattended workstation.
How do I fix CVE-2013-7221?
To fix CVE-2013-7221, upgrade GNOME Shell to version 3.10 or later, which addresses the automatic screen lock functionality vulnerability.
What versions of GNOME Shell are affected by CVE-2013-7221?
GNOME Shell versions prior to 3.10, including all versions from 3.0.0 to 3.9.92, are affected by CVE-2013-7221.
What is the impact of CVE-2013-7221?
The impact of CVE-2013-7221 is the ability for physically proximate attackers to execute arbitrary commands on a locked GNOME Shell session.
Is there a workaround for CVE-2013-7221?
A temporary workaround for CVE-2013-7221 is to disable the automatic lock functionality or ensure that the GNOME Shell is not left unattended.