Candidate: CVE-2014-3202 PublicDate: 2014-05-06 14:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3202 http://www.openwall.com/lists/oss-security/2014/05/03/1 http://www.openwall.com/lists/oss-security/2014/04/29/2 http://www.openwall.com/lists/oss-security/2014/04/26/2 http://www.openwall.com/lists/oss-security/2014/04/26/1 Description: Unity before 7.2.1 does not properly handle entry activation, which allows physically proximate attackers to bypass the lock screen by holding the ENTER key, which triggers the process to crash. Ubuntu-Description: Notes: jdstrand> fixed prior to release Bugs: https://bugs.launchpad.net/unity/+bug/1308750 https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1308572 Priority: high Discovered-by: Assigned-to: CVSS: Patches_unity: upstream_unity: needs-triage lucid_unity: DNE precise_unity: not-affected quantal_unity: not-affected saucy_unity: not-affected trusty_unity: released (7.2.0+14.04.20140416-0ubuntu1) trusty/esm_unity: DNE (trusty was released [7.2.0+14.04.20140416-0ubuntu1]) devel_unity: not-affected