CVE-2013-1940: Low severity x.org xserver vulnerability
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1940?
CVE-2013-1940 is considered a critical vulnerability due to its potential for exposing sensitive information.
How do I fix CVE-2013-1940?
To fix CVE-2013-1940, upgrade to X.Org X server version 1.13.4 or later, or 1.4.1 or later.
Who is affected by CVE-2013-1940?
CVE-2013-1940 affects X.Org X server versions prior to 1.13.4 and 1.4.x versions prior to 1.14.1, as well as specific versions of Ubuntu Linux.
What type of attack can CVE-2013-1940 facilitate?
CVE-2013-1940 can facilitate local attacks allowing access to sensitive information through unprotected input events.
Is there a workaround for CVE-2013-1940?
There is no official workaround for CVE-2013-1940, upgrading to a patched version is recommended.