First published: Mon Jun 01 2015(Updated: )
Ray Strode of Red Hat reports: Clutter contains APIs for recognizing finger and mouse movement based gestures. GNOME Shell uses these APIs to recognize when the user lifts the "screen shield" to initiate the screen unlock process (where a password would normally be entered). A bug in clutter's gesture handling code leads to a crash in some cases when the user performs gestures. This crash can lead to screen lock bypass. The bug was fixed upstream in clutter 1.16.2 External reference: <a href="https://bugzilla.gnome.org/show_bug.cgi?id=749847">https://bugzilla.gnome.org/show_bug.cgi?id=749847</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
libclutter-1.0-0 | <=1.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3213 is classified as a medium severity vulnerability.
To fix CVE-2015-3213, update Clutter to version 1.16.0 or later.
CVE-2015-3213 affects Clutter versions up to and including 1.16.0.
CVE-2015-3213 is a bug in Clutter's gesture recognition APIs.
Systems using vulnerable versions of Clutter for GNOME Shell are impacted by CVE-2015-3213.