CVE-2014-5195
Summary
| CVE | CVE-2014-5195 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-07 11:13:37 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switching to the lock screen, which allows physically proximate attackers to bypass the lock screen by (1) leveraging a machine that had text selected when locking or (2) resuming from a suspension. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ayatana Project | Unity | 7.2.0 | All | All | All |
| Application | Ayatana Project | Unity | 7.2.1 | All | All | All |
| Application | Ayatana Project | Unity | 7.3.0 | All | All | All |
| Application | Ayatana Project | Unity | All | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug #1349128 “Ubuntu 14.04 lock screen doesn't accept keyboard i...” : Series 7.2 : Bugs : Unity | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | |
| Ubuntu 'Unity' Package Lock Screen Local Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| USN-2303-1: Unity vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.osvdb.org/109788 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.