CVE-2013-7374: Medium severity Ubuntu vulnerability
The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 does not properly restrict access to Evolution, which allows local users to bypass the greeter screen restrictions by clicking the date.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ubuntu indicator-datetime (indicator-datetime / Ubuntu Date and Time Indicator)to a version that resolves this vulnerability.Fixed in 13.10.0+13.10.20131023.2-0ubuntu1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7374?
CVE-2013-7374 is classified as a medium-severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2013-7374?
To fix CVE-2013-7374, upgrade to the patched version 13.10.0+13.10.20131023.2-0ubuntu1.1 or later.
Who is affected by CVE-2013-7374?
CVE-2013-7374 affects users of Ubuntu Linux version 13.10.
What does CVE-2013-7374 allow an attacker to do?
CVE-2013-7374 allows local users to bypass the greeter screen restrictions by clicking on the date in the Date and Time Indicator.
When was CVE-2013-7374 reported?
CVE-2013-7374 was reported in April 2014, but it affects older versions of Ubuntu from October 2013.