CVE-2013-1940: Canonical Ubuntu Linux
Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty.
Affected products
- Canonical Ubuntu Linux: version 11.04 only; version 11.10 only; version 12.04 only; version 12.10 only
- X X.org-Xserver: up to and including 1.13.3; version 1.4.0 only
Published 2013-05-13. Last modified 2026-06-16.