First published: Thu May 01 2014(Updated: )
The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 does not properly restrict access to Evolution, which allows local users to bypass the greeter screen restrictions by clicking the date.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =13.10 | |
=13.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7374 is classified as a medium-severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2013-7374, upgrade to the patched version 13.10.0+13.10.20131023.2-0ubuntu1.1 or later.
CVE-2013-7374 affects users of Ubuntu Linux version 13.10.
CVE-2013-7374 allows local users to bypass the greeter screen restrictions by clicking on the date in the Date and Time Indicator.
CVE-2013-7374 was reported in April 2014, but it affects older versions of Ubuntu from October 2013.