CVE-2013-4509
Last modified
CVE-2013-4509 is a vulnerability of currently unknown severity. The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibus Project | Ibus | <= 1.5.2 |
| Ibus Project | Ibus | 1.5.4 |
| Opensuse | Opensuse | 13.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4509?
How severe is CVE-2013-4509?
How do I fix CVE-2013-4509?
Are you affected by CVE-2013-4509?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
