USN-6963-1: GNOME Shell vulnerability
It was discovered that GNOME Shell incorrectly opened the portal helper automatically when detecting a captive network portal. A remote attacker could possibly use this issue to load arbitrary web pages containing JavaScript, leading to resource consumption or other attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6963-1?
The severity of USN-6963-1 is considered significant due to the potential for resource consumption and unauthorized attacks via JavaScript.
How do I fix USN-6963-1?
To fix USN-6963-1, users should upgrade their GNOME Shell to the recommended versions specified in the advisory.
What systems are affected by USN-6963-1?
USN-6963-1 affects Ubuntu systems running GNOME Shell versions prior to 46.0-0ubuntu6~24.04.3, 42.9-0ubuntu2.2, and 3.36.9-0ubuntu0.20.04.4.
What type of attack is possible due to USN-6963-1?
Due to USN-6963-1, a remote attacker could exploit the flaw to load arbitrary web pages that could run malicious JavaScript.
Is it safe to use GNOME Shell on vulnerable systems referenced in USN-6963-1?
Using GNOME Shell on vulnerable systems is not safe as it may expose users to potential resource exhaustion and malicious web content.