CVE-2013-1940
published 2013-05-13CVE-2013-1940: X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.38%
30.2th percentile
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | xorg-server | < xorg-server 2:1.12.4-6 (bookworm) | xorg-server 2:1.12.4-6 (bookworm) |
| x.org | xorg-server | >= 0 < 2:1.12.4-6 | 2:1.12.4-6 |
| x.org | xorg-server | >= 0 < 2:1.12.4-6 | 2:1.12.4-6 |
| x.org | xorg-server | >= 0 < 2:1.12.4-6 | 2:1.12.4-6 |
| x.org | xorg-server | >= 0 < 2:1.12.4-6 | 2:1.12.4-6 |
| x | x.org-xserver | <= 1.13.3 | — |
| x | x.org-xserver | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xorg-x11-server: Information disclosure due enabling events from hot-plug devices despite input from the device being momentarily disabled
vendor_redhat·2013-04-17·CVSS 2.1
CVE-2013-1940 [LOW] xorg-x11-server: Information disclosure due enabling events from hot-plug devices despite input from the device being momentarily disabled
xorg-x11-server: Information disclosure due enabling events from hot-plug devices despite input from the device being momentarily disabled
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty.
Package: xorg-x11-server (Red Hat Enterprise Linux 5) - Not affected
Package: xorg-x11-server (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
X.Org X server vulnerability
vendor_ubuntu·2013-04-17
CVE-2013-1940 X.Org X server vulnerability
Title: X.Org X server vulnerability
Summary: The X server could be made to reveal keystrokes of other users.
It was discovered that the X.Org X server did not properly clear input
events in certain circumstances. A local attacker with physical access
could use this flaw to capture keystrokes.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Debian
CVE-2013-1940: xorg-server - X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict ...
vendor_debian·2013·CVSS 2.1
CVE-2013-1940 [LOW] CVE-2013-1940: xorg-server - X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict ...
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty.
Scope: local
bookworm: resolved (fixed in 2:1.12.4-6)
bullseye: resolved (fixed in 2:1.12.4-6)
forky: resolved (fixed in 2:1.12.4-6)
sid: resolved (fixed in 2:1.12.4-6)
trixie: resolved (fixed in 2:1.12.4-6)
GHSA
GHSA-hmm5-mg2w-wrfw: X
ghsa_unreviewed·2022-05-17
CVE-2013-1940 [LOW] GHSA-hmm5-mg2w-wrfw: X
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty.
OSV
CVE-2013-1940: X
osv·2013-05-13·CVSS 2.1
CVE-2013-1940 [LOW] CVE-2013-1940: X
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1940 xorg-x11-server: Information disclosure due enabling events from hot-plug devices despite input from the device being momentarily disabled [fedora-all]
bugzilla·2013-04-17·CVSS 2.1
CVE-2013-1940 [LOW] CVE-2013-1940 xorg-x11-server: Information disclosure due enabling events from hot-plug devices despite input from the device being momentarily disabled [fedora-all]
CVE-2013-1940 xorg-x11-server: Information disclosure due enabling events from hot-plug devices despite input from the device being momentarily disabled [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in
Bugzilla
CVE-2013-1940 xorg-x11-server: Information disclosure due enabling events from hot-plug devices despite input from the device being momentarily disabled
bugzilla·2013-04-10·CVSS 2.1
CVE-2013-1940 [LOW] CVE-2013-1940 xorg-x11-server: Information disclosure due enabling events from hot-plug devices despite input from the device being momentarily disabled
CVE-2013-1940 xorg-x11-server: Information disclosure due enabling events from hot-plug devices despite input from the device being momentarily disabled
An information disclosure flaw was found in the way X.org X11 server, an open source X Window System server implementation, used to register new hot-plug devices, when X.org X11 server was instructed (for that particular moment) not to receive input devices events. Formerly when registering new input device, X.org X11 server simultaneously enabled retrieval of input from the particular device (regardless of the setting). A local unsuspecting user, relying on the X.org X11 server disable input feature it to properly prohibit acquiring of events from this newly added hot-plug device, could supply a sensitive information that, due the above
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102391.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/104089.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00015.htmlhttp://www.debian.org/security/2013/dsa-2661http://www.openwall.com/lists/oss-security/2013/04/18/3http://www.ubuntu.com/usn/USN-1803-1https://bugs.freedesktop.org/show_bug.cgi?id=63353http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102391.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/104089.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00015.htmlhttp://www.debian.org/security/2013/dsa-2661http://www.openwall.com/lists/oss-security/2013/04/18/3http://www.ubuntu.com/usn/USN-1803-1https://bugs.freedesktop.org/show_bug.cgi?id=63353
2013-05-13
Published