VulnerabilityModified
CVE-2014-3202
Unity before 7.2.1 does not properly handle entry activation, which allows physically proximate attackers to bypass the lock screen by holding the ENTER key, which triggers the process to crash.
MEDIUM 4.4EPSS 0.42%
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
Unity before 7.2.1 does not properly handle entry activation, which allows physically proximate attackers to bypass the lock screen by holding the ENTER key, which triggers the process to crash.
- CVSS 2.0
- 4.4 MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.42% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ayatana project/unity
- Source
- security@ubuntu.com
References
- http://www.openwall.com/lists/oss-security/2014/04/26/1
- http://www.openwall.com/lists/oss-security/2014/04/26/2
- http://www.openwall.com/lists/oss-security/2014/04/29/2
- http://www.openwall.com/lists/oss-security/2014/05/03/1
- https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1308572
- https://bugs.launchpad.net/unity/+bug/1308750Exploit
- http://www.openwall.com/lists/oss-security/2014/04/26/1
- http://www.openwall.com/lists/oss-security/2014/04/26/2
- http://www.openwall.com/lists/oss-security/2014/04/29/2
- http://www.openwall.com/lists/oss-security/2014/05/03/1
- https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1308572
- https://bugs.launchpad.net/unity/+bug/1308750Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.