CVE-2015-1308: Infoleak
kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1308?
CVE-2015-1308 is considered to be of moderate severity due to the potential for remote attackers to obtain sensitive input events.
How do I fix CVE-2015-1308?
To fix CVE-2015-1308, update your software to a version later than plasma-workspace 5.1.95 or kde-workspace 4.2.0.
Which versions are affected by CVE-2015-1308?
CVE-2015-1308 affects kde-workspace versions up to and including 4.2.0 and plasma-workspace versions before 5.1.95.
What types of systems are vulnerable to CVE-2015-1308?
CVE-2015-1308 primarily affects systems running KDE Plasma Workspace and KDE Workspace prior to the specified versions.
Can CVE-2015-1308 lead to data breaches?
Yes, CVE-2015-1308 can potentially result in data breaches by allowing unauthorized access to passwords and other sensitive input events.