[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2661-1 xorg-server -- information disclosure

ID: oval:org.secpod.oval:def:601005Date: (C)2013-04-18   (M)2022-10-10
Class: PATCHFamily: unix




David Airlie and Peter Hutterer of Red Hat discovered that xorg-server, the Xorg X server was vulnerable to an information disclosure flaw related to input handling and devices hotplug. When an X server is running but not on front , a newly plugged input device would still be recognized and handled by the X server, which would actually transmit input events to its clients on the background. This could allow an attacker to recover some input events not intended for the X clients, including sensitive information.

Platform:
Debian 6.0
Product:
xserver-xorg-core
Reference:
DSA-2661-1
CVE-2013-1940
CVE    1
CVE-2013-1940
CPE    2
cpe:/o:debian:debian_linux:6.x
cpe:/a:x.org:xserver-xorg-core

© SecPod Technologies