cbcvebase.
CVE-2013-4509
published 2013-11-23

CVE-2013-4509: The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the…

PriorityP411low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.34%
26.6th percentile
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianibus-anthy< ibus-anthy 1.5.4-1 (bookworm)ibus-anthy 1.5.4-1 (bookworm)
debianibus-chewing< ibus-anthy 1.5.4-1 (bookworm)ibus-anthy 1.5.4-1 (bookworm)
debianibus-pinyin< ibus-anthy 1.5.4-1 (bookworm)ibus-anthy 1.5.4-1 (bookworm)
debianmozc< ibus-anthy 1.5.4-1 (bookworm)ibus-anthy 1.5.4-1 (bookworm)
ibus_projectibus<= 1.5.2
ibus_projectibus
opensuseopensuse

CVSS provenance

nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.