cbcvebase.
CVE-2013-4394
published 2013-10-28

CVE-2013-4394: The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts…

PriorityP419medium5.9CVSS 2.0
AVLACHAuNCCICAP
EPSS
0.34%
26.1th percentile
The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration file and possibly gain privileges via vectors involving "special and control characters."

Affected

7 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiansystemd< systemd 204-5 (bookworm)systemd 204-5 (bookworm)
systemd_projectsystemd< 194194
systemd_projectsystemd>= 0 < 204-5204-5
systemd_projectsystemd>= 0 < 204-5204-5
systemd_projectsystemd>= 0 < 204-5204-5
systemd_projectsystemd>= 0 < 204-5204-5

CVSS provenance

nvdv2.05.9MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.