CVE-2013-4509
published 2013-11-23CVE-2013-4509: The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the…
PriorityP411low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.34%
26.6th percentile
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ibus-anthy | < ibus-anthy 1.5.4-1 (bookworm) | ibus-anthy 1.5.4-1 (bookworm) |
| debian | ibus-chewing | < ibus-anthy 1.5.4-1 (bookworm) | ibus-anthy 1.5.4-1 (bookworm) |
| debian | ibus-pinyin | < ibus-anthy 1.5.4-1 (bookworm) | ibus-anthy 1.5.4-1 (bookworm) |
| debian | mozc | < ibus-anthy 1.5.4-1 (bookworm) | ibus-anthy 1.5.4-1 (bookworm) |
| ibus_project | ibus | <= 1.5.2 | — |
| ibus_project | ibus | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hfpc-f259-2f2x: The default configuration of IBUS 1
ghsa_unreviewed·2022-05-14
CVE-2013-4509 [LOW] GHSA-hfpc-f259-2f2x: The default configuration of IBUS 1
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.
OSV
CVE-2013-4509: The default configuration of IBUS 1
osv·2013-11-23·CVSS 1.9
CVE-2013-4509 [LOW] CVE-2013-4509: The default configuration of IBUS 1
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.
Red Hat
ibus: visible password entry flaw
vendor_redhat·2013-10-25·CVSS 1.9
CVE-2013-4509 [LOW] ibus: visible password entry flaw
ibus: visible password entry flaw
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.
Package: ibus-anthy (Red Hat Enterprise Linux 6) - Not affected
Package: ibus-chewing (Red Hat Enterprise Linux 6) - Not affected
Package: ibus-pinyin (Red Hat Enterprise Linux 6) - Not affected
Package: ibus-chewing (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4509: ibus-anthy - The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IB...
vendor_debian·2013·CVSS 1.9
CVE-2013-4509 [LOW] CVE-2013-4509: ibus-anthy - The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IB...
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.
Scope: local
bookworm: resolved (fixed in 1.5.4-1)
bullseye: resolved (fixed in 1.5.4-1)
forky: resolved (fixed in 1.5.4-1)
sid: resolved (fixed in 1.5.4-1)
trixie: resolved (fixed in 1.5.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4509 ibus-pinyin: ibus: visible password entry flaw [fedora-all]
bugzilla·2013-11-05·CVSS 1.9
CVE-2013-4509 [LOW] CVE-2013-4509 ibus-pinyin: ibus: visible password entry flaw [fedora-all]
CVE-2013-4509 ibus-pinyin: ibus: visible password entry flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-4509 ibus-chewing: ibus: visible password entry flaw [fedora-all]
bugzilla·2013-11-05·CVSS 1.9
CVE-2013-4509 [LOW] CVE-2013-4509 ibus-chewing: ibus: visible password entry flaw [fedora-all]
CVE-2013-4509 ibus-chewing: ibus: visible password entry flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affect
Bugzilla
CVE-2013-4509 ibus: visible password entry flaw
bugzilla·2013-11-05·CVSS 1.9
CVE-2013-4509 [LOW] CVE-2013-4509 ibus: visible password entry flaw
CVE-2013-4509 ibus: visible password entry flaw
It was reported [1] that IBUS 1.5.4 (and possibly 1.5.2) do not properly obscure password entry if a special "intent" is not provided.
A fix in ibus-anthy [2] illustrates what is necessary to provide the input purpose for the gnome-shell password dialog. A similar patch exists for ibus-mozc [3].
The SUSE bug report notes the following engines are affected:
* ibus-mozc
* ibus-anthy (upstream 1.5.4 is fixed; in current Fedora)
* ibus-pinyin
* ibus-chewing
The vulnerability is in these engines due to the changes in IBUS, so it only affects these engines when IBUS >= 1.5.4 (or 1.5.2, it hasn't been determine precisely from what I can see) and GNOME 3.6+ are used together.
[1] https://bugzilla.novell.com/show_bug.cgi?id=847718
[2] https://gi
http://lists.opensuse.org/opensuse-updates/2013-11/msg00036.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00024.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00045.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1027028https://code.google.com/p/mozc/issues/attachmentText?id=199&aid=1990002000&name=ibus-mozc_support_ibus-1.5.4_rev2.diff&token=P62umpXGXx68XJT6zyvBA727wqE%3A1383693105690https://github.com/ibus/ibus-anthy/commit/6aae0a9f145f536515e268dd6b25aa740a5edfe7https://groups.google.com/forum/#%21topic/ibus-user/mvCHDO1BJUwhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00036.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00024.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00045.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1027028https://code.google.com/p/mozc/issues/attachmentText?id=199&aid=1990002000&name=ibus-mozc_support_ibus-1.5.4_rev2.diff&token=P62umpXGXx68XJT6zyvBA727wqE%3A1383693105690https://github.com/ibus/ibus-anthy/commit/6aae0a9f145f536515e268dd6b25aa740a5edfe7https://groups.google.com/forum/#%21topic/ibus-user/mvCHDO1BJUw
2013-11-23
Published