First published: Thu Sep 17 2015(Updated: )
The Unity Settings Daemon before 14.04.0+14.04.20150825-0ubuntu2 and 15.04.x before 15.04.1+15.04.20150408-0ubuntu1.2 does not properly detect if the screen is locked, which allows physically proximate attackers to mount removable media while the screen is locked as demonstrated by inserting a USB thumb drive.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =14.04 | |
Ubuntu | =15.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1319 has a medium severity level due to the potential for physical access attacks.
To fix CVE-2015-1319, upgrade to Unity Settings Daemon version 14.04.0+14.04.20150825-0ubuntu2 or 15.04.1+15.04.20150408-0ubuntu1.2 or later.
CVE-2015-1319 affects Ubuntu Linux versions 14.04 and 15.04 before their respective patches were applied.
The impact of CVE-2015-1319 is that attackers with physical access can insert removable media while the screen is locked.
CVE-2015-1319 is not user-exploitable remotely but can be exploited by physical attackers with direct access to the system.