CVE-2015-1308

Publication date 26 January 2015

Last updated 24 July 2024


Ubuntu priority

kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.

Read the notes from the security team

Status

Package Ubuntu Release Status
kde-workspace 17.04 zesty Not in release
16.10 yakkety Not in release
16.04 LTS xenial Not in release
15.10 wily Not in release
15.04 vivid Not in release
14.10 utopic Ignored end of life
14.04 LTS trusty Not in release
12.04 LTS precise Ignored end of life
10.04 LTS lucid Not in release

Notes


mdeslaur

under X, apps can pretty much sniff input events anyway


tsimonq2

The only release that is affected by this is Trusty, and upstream recommends against backporting a fix (it's low priority anyways) Reference: https://bugzilla.redhat.com/show_bug.cgi?id=1183710#c5

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
kde-workspace