USN-1803-1: X.Org X server vulnerability
17 April 2013
The X server could be made to reveal keystrokes of other users.
Releases
Packages
- xorg-server - X.Org X server
- xorg-server-lts-quantal - X.Org X server
Details
It was discovered that the X.Org X server did not properly clear input
events in certain circumstances. A local attacker with physical access
could use this flaw to capture keystrokes.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.10
Ubuntu 12.04
-
xserver-xorg-core-lts-quantal
-
2:1.13.0-0ubuntu6.1~precise3
-
xserver-xorg-core
-
2:1.11.4-0ubuntu10.13
Ubuntu 11.10
Ubuntu 10.04
After a standard system update you need to restart your session to make
all the necessary changes.