The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.
CVSS Details
- CVSS 3.1 Base Score: 4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ibus-chewingUpgrade mozcUpgrade ibus-anthyUpgrade ibus-pinyin | Jul 30, 2024 | Nov 23, 2013 |
| Suse | — | Upgrade ibus-branding-openSUSE-KDEUpgrade ibus-develUpgrade ibus-gtk3-32bitUpgrade ibus-pinyinUpgrade ibus-langUpgrade libibus-1_0-5-32bitUpgrade ibus-gtkUpgrade python-ibusUpgrade ibus-gtk3Upgrade typelib-1_0-IBus-1_0Upgrade ibus-chewingUpgrade ibus-gtk-32bitUpgrade libibus-1_0-5Upgrade ibus | Dec 12, 2013 | Nov 23, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub