Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2013-4509

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

IBUS(Intelligent Input Bus)是一套下一代输入法框架(平台),它包含了世界多数语言的文字输入需求。 IBUS 1.5.4和1.5.2及之前版本的默认配置中存在安全漏洞,该漏洞源于当程序使用GNOME 3并未设置使用IBus.InputPurpose.PASSWORD时,没有遮挡输入的密码。物理位置临近的攻击者可通过查看锁定屏幕利用该漏洞获取用户密码。

AI Predicted 4.4 Difficulty: Trivial EPSS 0.34% · P27
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2013-4509

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
IBus 本地密码信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBUS(Intelligent Input Bus)是一套下一代输入法框架(平台),它包含了世界多数语言的文字输入需求。 IBUS 1.5.4和1.5.2及之前版本的默认配置中存在安全漏洞,该漏洞源于当程序使用GNOME 3并未设置使用IBus.InputPurpose.PASSWORD时,没有遮挡输入的密码。物理位置临近的攻击者可通过查看锁定屏幕利用该漏洞获取用户密码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2013-4509

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-4509

登录查看更多情报信息。

Patches & Fixes for CVE-2013-4509 (1)

Vendor Advisories for CVE-2013-4509 (1)

Mailing List Discussions for CVE-2013-4509 (3)

Other References for CVE-2013-4509 (2)

Same Patch Batch · n/a · 2013-11-23 · 60 CVEs total

CVE-2013-0867 FFmpeg libavcodec/h264.c ‘decode_slice_header()’函数安全漏洞
CVE-2013-4164 Ruby 基于堆的缓冲区溢出漏洞
CVE-2013-6866 SAP Sybase Adaptive Server Enterprise 安全漏洞
CVE-2013-6865 SAP Sybase Adaptive Server Enterprise 安全漏洞
CVE-2013-6864 SAP Sybase Adaptive Server Enterprise 目录遍历漏洞
CVE-2013-6867 SAP Sybase Adaptive Server Enterprise 安全漏洞
CVE-2013-2561 OpenFabrics ibutils 不安全临时文件漏洞
CVE-2013-1058 Ubuntu MAAS Server 中间人攻击漏洞
CVE-2013-0869 FFmpeg libavcodec/h264.c ‘field_end()’函数安全漏洞
CVE-2013-0868 FFmpeg libavcodec/huffyuvdec.c文件整数溢出漏洞
CVE-2013-4459 LightDM ‘create_guest_session()’函数安全绕过漏洞
CVE-2013-0866 FFmpeg libavcodec/aacdec.c ‘aac_decode_init()’函数边界错误漏洞
CVE-2013-0865 FFmpeg libavcodec/vqavideo.c ‘vqa_decode_chunk()’函数边界错误漏洞
CVE-2013-0864 FFmpeg libavcodec/gifdec.c ‘gif_copy_img_rect()’函数拒绝服务漏洞
CVE-2013-0863 FFmpeg libavcodec/sanm.c ‘rle_decode’函数缓冲区溢出漏洞
CVE-2013-0862 FFmpeg ‘ibavcodec/sanm.c process_frame_obj()’函数整数溢出漏洞
CVE-2013-0861 FFmpeg ‘avcodec_decode_audio4’函数拒绝服务漏洞
CVE-2013-0860 FFmpeg ‘ff_er_frame_end’函数拒绝服务漏洞
CVE-2013-0223 GNU coreutils 缓冲区错误漏洞
CVE-2013-0222 GNU coreutils 缓冲区错误漏洞

Showing top 20 of 60 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2013-4509

No comments yet


Leave a comment