CVE-2013-4509: Ibus Project Ibus
Low severity, CVSS 1.9. EPSS: 0.3% chance of exploitation in the next 30 days.
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.
Affected products
- Ibus Project Ibus: up to and including 1.5.2; version 1.5.4 only
- Opensuse Opensuse: version 13.1 only
Published 2013-11-23. Last modified 2026-06-16.