PT-2015-5200 · Kde · Kde-Workspace+1
Albert Astals Cid
·
Published
2015-01-26
·
Updated
2024-06-17
·
CVE-2015-1308
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
kde-workspace version 4.2.0
plasma-workspace versions prior to 5.1.95
Description
The issue allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.
Recommendations
For kde-workspace version 4.2.0, update to a version later than 4.2.0 to resolve the issue.
For plasma-workspace versions prior to 5.1.95, update to version 5.1.95 or later to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kde-Workspace
Plasma-Workspace