{"id":"MGASA-2014-0374","summary":"Updated gtk+3.0 packages fix CVE-2014-1949","details":"Updated gtk+3.0 packages fix security vulnerability:\n\nClemens Fries reported that, when using Cinnamon, it was possible to bypass\nthe screensaver lock. An attacker with physical access to the machine could\nuse this flaw to take over the locked desktop session (CVE-2014-1949).\n\nThis was fixed by including a patch for the root cause of the issue in\ngtk+3.0, which came from the implementation of popup menus in GtkWindow\n(bgo#722106).\n\nThis update also includes other patches from upstream to fix bugs affecting\nGtkFileChooser (bgo#386569, bgo#719977) and GtkSpinButton (bgo#709491), and a\ncrash related to clipboard handling (bgo#719314).\n","modified":"2026-04-16T06:24:57.348977533Z","published":"2014-09-09T09:34:16Z","upstream":["CVE-2014-1949"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0374.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14013"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=386569"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=709491"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=719314"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=719977"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=722106"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2014-August/137123.html"}],"affected":[{"package":{"name":"gtk+3.0","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/gtk+3.0?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"gtk+3.0-3.10.6-4.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0374.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}