PT-2018-3735 · Rosa Laboratory+3 · Rosa Linux+3

Publicado

2018-12-20

·

Atualizado

2018-12-20

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions X Window System (affected versions not specified) ALT Linux (affected versions not specified) ROSA Linux (affected versions not specified) МСВСфера (affected versions not specified)
Description The issue is related to the lack of validation when one application creates a child window inside another application's window. This could allow an attacker to intercept keyboard input by creating a malicious application that runs with low privileges and captures data entered into other application windows.
Recommendations For X Window System, consider restricting access to sensitive windows until a fix is available. For ALT Linux, ROSA Linux, and МСВСфера, at the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-04085

Produtos afetados

Alt Linux
Rosa Linux
X-Window-System
Мсвсфера