CVE-2019-3820: Medium severity IBM Data Risk Manager vulnerability
Gnome gnome-shell lock screen could allow a physical attacker to bypass security restrictions, caused by the failure to properly restrict all contextual actions. By performing specially-crafted operations, an attacker could exploit this vulnerability to invoke certain keyboard shortcuts.
Other sources
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3820?
CVE-2019-3820 has a medium severity rating due to its potential to allow physical attackers to bypass the lock screen security measures.
How do I fix CVE-2019-3820?
To fix CVE-2019-3820, update to the latest patched version of gnome-shell provided by your distribution.
Which versions of gnome-shell are affected by CVE-2019-3820?
CVE-2019-3820 affects gnome-shell versions prior to 3.30.3 and between 3.31.0 and 3.31.5.
What platforms are affected by CVE-2019-3820?
CVE-2019-3820 affects multiple platforms, including various releases of Ubuntu, openSUSE, and Debian.
Is there a workaround for CVE-2019-3820?
There is no official workaround for CVE-2019-3820, so upgrading to a secure version is recommended.