kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.
References
Information
Published : 2015-01-26 07:59
Updated : 2015-01-26 11:40
NVD link : CVE-2015-1308
Mitre link : CVE-2015-1308
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
kde
- plasma-workspace
- kde-workspace