← Back

CVE-2013-1940

nvd nist
Published: May 13, 2013Modified: Apr 29, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty.

Affected (6)

1 product
X.org Xserver
1 product
Ubuntu Linux
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
X
Up to 1.13.3
Version 1.4.0
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 11.04
Version 11.10
Version 12.04
Version 12.10

Related CWEs

Timeline

No history available yet.