CVE-2013-4509
Summary
| CVE | CVE-2013-4509 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-11-23 19:55:00 UTC |
| Updated | 2023-02-13 04:47:00 UTC |
| Description | The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen. |
Risk And Classification
Problem Types: CWE-255
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibus Project | Ibus | 1.5.4 | All | All | All |
| Application | Ibus Project | Ibus | 1.5.4 | All | All | All |
| Application | Ibus Project | Ibus | All | All | All | All |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| openSUSE-SU-2013:1825-1: ibus-pinyin: fixed typed password visibility | SUSE | lists.opensuse.org | |
| openSUSE-SU-2014:0068-1: moderate: update for ibus-chewing | SUSE | lists.opensuse.org | |
| ibus-mozc_support_ibus-1.5.4_rev2.diff (9.8 KB) - mozc - Mozc - Japanese Input Method for Chromium OS, Android, Windows, Mac and Linux - Google Project Hosting | CONFIRM | code.google.com | Patch |
| openSUSE-SU-2013:1686-1: ibus: avoid showing the password ont he GNOME l | SUSE | lists.opensuse.org | |
| Google Groups | MISC | groups.google.com | |
| Added to check the input purpose for gnome-shell password dialog. · ibus/ibus-anthy@6aae0a9 · GitHub | CONFIRM | github.com | Patch |
| 1027028 – (CVE-2013-4509) CVE-2013-4509 ibus: visible password entry flaw | CONFIRM | bugzilla.redhat.com | |
| Redirecting to Google Groups | MISC | groups.google.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.