CVE-2019-14822
published 2019-11-25CVE-2019-14822: A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due…
PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.36%
29.1th percentile
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | ibus | < ibus 1.5.21-1 (bookworm) | ibus 1.5.21-1 (bookworm) |
| ibus_project | ibus | < 1.5.22 | 1.5.22 |
| ibus_project | ibus | — | — |
| ibus_project | ibus | >= 0 < 1.5.21-1 | 1.5.21-1 |
| ibus_project | ibus | >= 0 < 1.5.21-1 | 1.5.21-1 |
| ibus_project | ibus | >= 0 < 1.5.21-1 | 1.5.21-1 |
| ibus_project | ibus | >= 0 < 1.5.21-1 | 1.5.21-1 |
| oracle | zfs_storage_appliance_kit | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6vhv-qmhp-gxj3: A flaw was discovered in ibus that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfigura
ghsa_unreviewed·2022-05-24
CVE-2019-14822 [LOW] CWE-862 GHSA-6vhv-qmhp-gxj3: A flaw was discovered in ibus that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfigura
A flaw was discovered in ibus that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.
OSV
CVE-2019-14822: A flaw was discovered in ibus in versions before 1
osv·2019-11-25·CVSS 7.1
CVE-2019-14822 [HIGH] CVE-2019-14822: A flaw was discovered in ibus in versions before 1
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.
Ubuntu
IBus vulnerability
vendor_ubuntu·2020-03-24
CVE-2019-14822 IBus vulnerability
Title: IBus vulnerability
Summary: IBus could allow local users to capture key strokes of other locally logged
in users.
USN-4134-1 fixed a vulnerability in IBus. The update caused a regression in
some Qt applications and the fix was subsequently reverted in
USN-4134-2. The regression has since been resolved and so this update fixes
the original vulnerability.
We apologize for the inconvenience.
Original advisory details:
Simon McVittie discovered that IBus did not enforce appropriate access
controls on its private D-Bus socket. A local unprivileged user who
discovers the IBus socket address of another user could exploit this to
capture the key strokes of the other user.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
IBus vulnerability
vendor_ubuntu·2019-09-16
CVE-2019-14822 IBus vulnerability
Title: IBus vulnerability
Summary: IBus would allow local users to capture key strokes of other locally logged
in users.
Simon McVittie discovered that IBus did not enforce appropriate access
controls on its private D-Bus socket. A local unprivileged user who
discovers the IBus socket address of another user could exploit this to
capture the key strokes of the other user.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
ibus: missing authorization allows local attacker to access the input bus of another user
vendor_redhat·2019-09-13·CVSS 7.1
CVE-2019-14822 [HIGH] CWE-862 ibus: missing authorization allows local attacker to access the input bus of another user
ibus: missing authorization allows local attacker to access the input bus of another user
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.
A flaw was discovered in ibus that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphica
Debian
CVE-2019-14822: ibus - A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivil...
vendor_debian·2019·CVSS 7.1
CVE-2019-14822 [HIGH] CVE-2019-14822: ibus - A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivil...
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.
Scope: local
bookworm: resolved (fixed in 1.5.21-1)
bullseye: resolved (fixed in 1.5.21-1)
forky: resolved (fixed in 1.5.21-1)
sid: resolved (fixed in 1.5.21-1)
trixie: resolved (fixed in 1.5.21-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14822 ibus: missing authorization allows local attacker to access the input bus of another user [fedora-all]
bugzilla·2019-09-13·CVSS 7.1
CVE-2019-14822 [HIGH] CVE-2019-14822 ibus: missing authorization allows local attacker to access the input bus of another user [fedora-all]
CVE-2019-14822 ibus: missing authorization allows local attacker to access the input bus of another user [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2019-14822 ibus: missing authorization allows local attacker to access the input bus of another user
bugzilla·2019-06-06·CVSS 7.1
CVE-2019-14822 [HIGH] CVE-2019-14822 ibus: missing authorization allows local attacker to access the input bus of another user
CVE-2019-14822 ibus: missing authorization allows local attacker to access the input bus of another user
ibus uses a GDBusServer with G_DBUS_SERVER_FLAGS_AUTHENTICATION_ALLOW_ANONYMOUS, and doesn't set a GDBusAuthObserver, which allows anyone who can connect to its AF_UNIX socket to authenticate and be authorized to send method calls. It also seems to use an abstract AF_UNIX socket, which does not have filesystem permissions, so the practical effect might be that a local attacker can connect to another user's ibus service and make arbitrary method calls.
Discussion:
An attacker who can access the AF_UNIX socket of another user could use it to monitor all the DBus methods called on the bus or call most available methods without any authorization check. This flaw could be used to intercep
https://bugzilla.redhat.com/show_bug.cgi?id=1717958https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14822https://usn.ubuntu.com/4134-3/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1717958https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14822https://usn.ubuntu.com/4134-3/https://www.oracle.com/security-alerts/cpuapr2022.html
2019-11-25
Published