CVE-2013-1940

X.Org X server <1.13.4/1.14.x<1.14.1 - Unauthenticated Sensitive Information Exposure

Title source: llm
STIX 2.1

Description

X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty.

References (7)

Core 7
Core References
Various Sources x_refsource_confirm
https://bugs.freedesktop.org/show_bug.cgi?id=63353
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1803-1
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/104089.html
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-06/msg00015.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2661
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/04/18/3
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102391.html

Scores

EPSS 0.0038
EPSS Percentile 30.0%

Details

CWE
CWE-264
Status published
Products (6)
canonical/ubuntu_linux 11.04
canonical/ubuntu_linux 11.10
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
x/x.org-xserver 1.4.0
x/x.org-xserver < 1.13.3
Published May 13, 2013
Tracked Since Feb 18, 2026