CVE-2014-7300
EPSS 0.47%
描述
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.
如何修補 CVE-2014-7300
要修補 CVE-2014-7300,請將受影響套件升級到下列已修補版本。
- Debian/gnome-shell—升級至 3.14.1-1 或更新版本
CVE-2014-7300 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 3.14.1-1