Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14822

Опубликовано: 13 сент. 2019
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.

A flaw was discovered in ibus that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.

Отчет

Gnome uses the ibus input framework only when the user explicitly configures it or when some input method sources are in use, like Korean from the ibus-hangul package or Chinese input methods from the ibus-libpinyin. Input methods like en-US are not handled by ibus, thus if the victim user just use them the attacker will not be able to intercept the key strokes of that user.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ibusOut of support scope
Red Hat Enterprise Linux 7glib2FixedRHSA-2020:397829.09.2020
Red Hat Enterprise Linux 7ibusFixedRHSA-2020:397829.09.2020
Red Hat Enterprise Linux 8glib2FixedRHSA-2020:188028.04.2020
Red Hat Enterprise Linux 8ibusFixedRHSA-2020:188028.04.2020
Red Hat Enterprise Linux 8glib2FixedRHSA-2020:188028.04.2020
Red Hat Enterprise Linux 8ibusFixedRHSA-2020:188028.04.2020
Red Hat OpenShift Doopenshiftdo/odo-init-image-rhel7FixedRHSA-2021:094922.03.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=1717958ibus: missing authorization allows local attacker to access the input bus of another user

EPSS

Процентиль: 48%
0.00246
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 6 лет назад

A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.

CVSS3: 7.1
nvd
почти 6 лет назад

A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.

CVSS3: 7.1
debian
почти 6 лет назад

A flaw was discovered in ibus in versions before 1.5.22 that allows an ...

suse-cvrf
почти 6 лет назад

Security update for ibus

suse-cvrf
почти 6 лет назад

Security update for ibus

EPSS

Процентиль: 48%
0.00246
Низкий

6.1 Medium

CVSS3