CVE-2014-7300: High severity gnome-shell vulnerability
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7300?
CVE-2014-7300 is classified as a high severity vulnerability due to its potential to allow arbitrary command execution.
How do I fix CVE-2014-7300?
To address CVE-2014-7300, update GNOME Shell to version 3.14.1 or later.
Which software is affected by CVE-2014-7300?
CVE-2014-7300 affects GNOME Shell versions 3.14.0 and is also relevant for Red Hat Enterprise Linux 7.0.
What are the risks associated with CVE-2014-7300?
The risks include unauthorized access to an unattended workstation by executing arbitrary commands.
Can CVE-2014-7300 be exploited remotely?
CVE-2014-7300 requires physical proximity, making it less likely to be exploited remotely.