1.9
CVSSv2

CVE-2013-4509

Published: 23/11/2013 Updated: 13/02/2023
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The default configuration of IBUS 1.5.4, and possibly 1.5.2 and previous versions, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate malicious users to obtain a user password by reading the lockscreen.

Vulnerable Product Search on Vulmon Subscribe to Product

ibus project ibus 1.5.4

ibus project ibus

opensuse opensuse 13.1

Vendor Advisories

Debian Bug report logs - #729065 ibus: CVE-2013-4509 Package: ibus; Maintainer for ibus is Debian Input Method Team <debian-input-method@listsdebianorg>; Source for ibus is src:ibus (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 8 Nov 2013 13:51:02 UTC Severity: important Tags: ...
The default configuration of IBUS 154, and possibly 152 and earlier, when IBusInputPurposePASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen ...