LOW
ibus: visible password entry flaw
Published Nov 23, 2013
1.9
LOWCVSS 2.0
EPSS 0.34%
Description
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.
Affected products
No data.
Configuration 1
OR
- ≤ 1.5.2
- 1.5.4
No data.
Red Hat Enterprise Linux 6
ibus-anthy
Not affected
Red Hat Enterprise Linux 6
ibus-chewing
Not affected
Red Hat Enterprise Linux 6
ibus-pinyin
Not affected
Red Hat Enterprise Linux 7
ibus-chewing
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | ibus-anthy | Not affected | n/a |
| Red Hat Enterprise Linux 6 | ibus-chewing | Not affected | n/a |
| Red Hat Enterprise Linux 6 | ibus-pinyin | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ibus-chewing | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://lists.opensuse.org/opensuse-updates/2013-11/msg00036.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00024.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00045.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2013-4509 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1027028 x_refsource_CONFIRMIssue Tracking
- https://code.google.com/p/mozc/issues/attachmentText?id=199&aid=1990002000&name=ibus-mozc_support_ibus-1.5.4_rev2.diff&token=P62umpXGXx68XJT6zyvBA727wqE%3A1383693105690 x_refsource_CONFIRMPatch
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-4370 Advisory
- https://github.com/ibus/ibus-anthy/commit/6aae0a9f145f536515e268dd6b25aa740a5edfe7 x_refsource_CONFIRMPatch
- https://groups.google.com/forum/#%21topic/ibus-user/mvCHDO1BJUw x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2013-4509
- https://www.cve.org/CVERecord?id=CVE-2013-4509
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 23, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4509
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-4370 Assigner redhat
Published Nov 23, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-4370