[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] CVE-2017-8288: gnome-shell may leave extensions enabled in the lock screen
From:       Emilio Pozuelo Monfort <pochu () debian ! org>
Date:       2017-04-27 8:04:06
Message-ID: a51da883-9c17-1e80-d081-20f1bf01199b () debian ! org
[Download RAW message or body]

Hi,

The following CVE was assigned to gnome-shell. Note this may affect earlier
versions than 3.22, but I didn't check them.

[Suggested description]
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload,
which can lead to leaving extensions enabled in the lock screen.
With these extensions, a bystander could
launch applications (but not interact with them), see information from
the extensions (e.g., what applications you have opened or what music
you were playing), or even execute arbitrary commands. It all
depends on what extensions a user has enabled. The problem is caused by lack of
exception handling in
js/ui/extensionSystem.js.

------------------------------------------

[Vulnerability Type]
Incorrect Access Control

------------------------------------------

[VulnerabilityType Other]
Incorrect Access Control

------------------------------------------

[Vendor of Product]
GNOME

------------------------------------------

[Affected Product Code Base]
gnome-shell - 3.22 - 3.25

------------------------------------------

[Affected Component]
js/ui/extensionSystem.js

------------------------------------------

[Attack Type]
Physical

------------------------------------------

[Impact Code execution]
true

------------------------------------------

[Impact Information Disclosure]
true

------------------------------------------

[Attack Vectors]
A broken gnome-shell extension needs to be installed (broken as in may
work normally, but has a bug where it fails to reload properly)

An extension reload needs to be triggered (which can happen for multiple reasons)

------------------------------------------

[Reference]
https://bugzilla.gnome.org/show_bug.cgi?id=781728
https://github.com/EasyScreenCast/EasyScreenCast/issues/46
https://bugs.kali.org/view.php?id=2513
https://github.com/GNOME/gnome-shell/commit/ff425d1db7082e2755d2a405af53861552acf2a1
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic