CVE-2015-3213: High severity libclutter-1.0-0 vulnerability
Ray Strode of Red Hat reports:
Clutter contains APIs for recognizing finger and mouse movement based gestures. GNOME Shell uses these APIs to recognize when the user lifts the "screen shield" to initiate the screen unlock process (where a password would normally be entered).
A bug in clutter's gesture handling code leads to a crash in some cases when the user performs gestures. This crash can lead to screen lock bypass. The bug was fixed upstream in clutter 1.16.2
External reference: https://bugzilla.gnome.org/showbug.cgi?id=749847
Other sources
The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via certain (1) mouse or (2) touch gestures.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3213?
CVE-2015-3213 is classified as a medium severity vulnerability.
How do I fix CVE-2015-3213?
To fix CVE-2015-3213, update Clutter to version 1.16.0 or later.
Which versions of Clutter are affected by CVE-2015-3213?
CVE-2015-3213 affects Clutter versions up to and including 1.16.0.
What type of vulnerability is CVE-2015-3213?
CVE-2015-3213 is a bug in Clutter's gesture recognition APIs.
What systems are impacted by CVE-2015-3213?
Systems using vulnerable versions of Clutter for GNOME Shell are impacted by CVE-2015-3213.