CVE-2014-3203
Summary
| CVE | CVE-2014-3203 |
|---|---|
| State | PUBLISHED |
| Assigner | canonical |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-05-06 14:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Unity before 7.2.1, as used in Ubuntu 14.04, does not properly restrict access to the Dash when the lock screen is active, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by pressing the SUPER key before the screen auto-locks. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ayatana Project | Unity | 7.0.0 | All | All | All |
| Application | Ayatana Project | Unity | 7.0.1 | All | All | All |
| Application | Ayatana Project | Unity | 7.1.0 | All | All | All |
| Application | Ayatana Project | Unity | 7.1.1 | All | All | All |
| Application | Ayatana Project | Unity | 7.1.2 | All | All | All |
| Application | Ayatana Project | Unity | 7.1.3 | All | All | All |
| Application | Ayatana Project | Unity | All | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-2184-1: Unity vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | Vendor Advisory |
| oss-security - Re: Ubuntu 14.04: security problem in the lock screen | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - Re: Ubuntu 14.04: security problem in the lock screen | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Bug #1308850 “Dash is visible on top of the lockscreen after scr...” : Bugs : “unity” package : Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.