PT-2018-3735 · Rosa Laboratory+3 · Rosa Linux+3
Published
2018-12-20
·
Updated
2018-12-20
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
X Window System (affected versions not specified)
ALT Linux (affected versions not specified)
ROSA Linux (affected versions not specified)
МСВСфера (affected versions not specified)
Description
The issue is related to the lack of validation when one application creates a child window inside another application's window. This could allow an attacker to intercept keyboard input by creating a malicious application that runs with low privileges and captures data entered into other application windows.
Recommendations
For X Window System, consider restricting access to sensitive windows until a fix is available.
For ALT Linux, ROSA Linux, and МСВСфера, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Rosa Linux
X-Window-System
Мсвсфера