js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities search.
{ "binaries": [ { "binary_version": "3.10.4-0ubuntu5.2", "binary_name": "gnome-shell" }, { "binary_version": "3.10.4-0ubuntu5.2", "binary_name": "gnome-shell-common" }, { "binary_version": "3.10.4-0ubuntu5.2", "binary_name": "gnome-shell-dbg" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "3.18.5-0ubuntu0.3", "binary_name": "gnome-shell" }, { "binary_version": "3.18.5-0ubuntu0.3", "binary_name": "gnome-shell-common" }, { "binary_version": "3.18.5-0ubuntu0.3", "binary_name": "gnome-shell-dbg" }, { "binary_version": "3.18.5-0ubuntu0.3", "binary_name": "gnome-shell-dbgsym" } ], "availability": "No subscription required" }