CVE-2013-1940
13.05.2013, 23:55
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| x | x.org-xserver | 𝑥 ≤ 1.13.3 |
| x | x.org-xserver | 1.4.0 |
| canonical | ubuntu_linux | 11.04 |
| canonical | ubuntu_linux | 11.10 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-server |
| ||||||||||
| xorg-server-lts-quantal |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-x11-server |
| ||||||||||
| xorg-x11-server-extra |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| xorg-x11-server-Xdmx |
| ||
| xorg-x11-server-Xephyr |
| ||
| xorg-x11-server-Xnest |
| ||
| xorg-x11-server-Xorg |
| ||
| xorg-x11-server-Xvfb |
| ||
| xorg-x11-server-common |
| ||
| xorg-x11-server-devel |
| ||
| xorg-x11-server-source |
|
Common Weakness Enumeration
References