CVE-2019-14822

Source
https://cve.org/CVERecord?id=CVE-2019-14822
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14822.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-14822
Downstream
Related
Published
2019-11-25T12:15:11.427Z
Modified
2026-02-12T08:26:12.792446Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.

References

Affected packages

Git / github.com/ibus/ibus

Affected ranges

Type
GIT
Repo
https://github.com/ibus/ibus
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*
0.1.0.20080810
0.1.1.20080812
0.1.1.20080815
0.1.1.20080821
0.1.1.20080823
0.1.1.20080830
0.1.1.20081023
1.*
1.1.0.20090211
1.1.0.20090217
1.1.0.20090225
1.1.0.20090306
1.1.0.20090311
1.1.0.20090331
1.1.0.20090407
1.1.0.20090413
1.1.0.20090417
1.1.0.20090423
1.1.0.20090508
1.1.0.20090531
1.1.0.20090609
1.1.0.20090612
1.2.0.20090617
1.2.0.20090719
1.2.0.20090722
1.2.0.20090723
1.2.0.20090806
1.2.0.20090807
1.2.0.20090810
1.2.0.20090812
1.2.0.20090828
1.2.0.20090904
1.2.0.20090915
1.2.0.20090927
1.2.0.20091014
1.2.0.20091024
1.2.0.20091124
1.2.0.20091204
1.2.0.20091215
1.2.0.20091225
1.2.0.20100111
1.2.99.20100202
1.2.99.20100322
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.4.0
1.4.1
1.4.99.20121006
1.4.99.20121109
1.5.0
1.5.1
1.5.10
1.5.11
1.5.12
1.5.13
1.5.14
1.5.15
1.5.16
1.5.17
1.5.18
1.5.19
1.5.2
1.5.20
1.5.21
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
Other
20080901

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14822.json"

Git / github.com/pnggroup/libpng

Affected ranges

Type
GIT
Repo
https://github.com/pnggroup/libpng
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

libpng-1.*
libpng-1.5.16-signed
libpng-1.5.17-signed
libpng-1.5.18-signed
libpng-1.5.20-signed
libpng-1.5.21-signed
v0.*
v0.71
v0.81
v0.82
v0.85
v0.86
v0.87
v0.88
v0.89
v0.89c
v0.90
v0.96
v0.97
v0.97a
v0.97c
v0.98
v0.99
v0.99a
v0.99c
v0.99d
v0.99e
v0.99i
v0.99j
v0.99k
v0.99m
v0.99n
v0.99p
v1.*
v1.0.0
v1.0.0a
v1.0.0b
v1.0.1
v1.0.10
v1.0.10beta1
v1.0.10rc1
v1.0.11
v1.0.11beta1
v1.0.11beta2
v1.0.11beta3
v1.0.11rc1
v1.0.12beta1
v1.0.1a
v1.0.1b
v1.0.1c
v1.0.1d
v1.0.1e
v1.0.2
v1.0.2a
v1.0.2b
v1.0.3
v1.0.4
v1.0.4-pre1
v1.0.4-pre2
v1.0.4-pre3
v1.0.4c
v1.0.4d
v1.0.4d2
v1.0.4e
v1.0.4f
v1.0.5
v1.0.5-pre1
v1.0.5a
v1.0.5c
v1.0.5d
v1.0.5h
v1.0.5q
v1.0.5s
v1.0.6
v1.0.6a
v1.0.6d
v1.0.6e
v1.0.6f
v1.0.6g
v1.0.6h
v1.0.6i
v1.0.6j
v1.0.7
v1.0.7beta11
v1.0.7beta12
v1.0.7beta13
v1.0.7beta14
v1.0.7beta15
v1.0.7beta16
v1.0.7beta17
v1.0.7beta18
v1.0.7rc1
v1.0.7rc2
v1.0.8
v1.0.8beta1
v1.0.8beta2
v1.0.8beta3
v1.0.8beta4
v1.0.8rc1
v1.0.9
v1.0.9beta1
v1.0.9beta10
v1.0.9beta2
v1.0.9beta3
v1.0.9beta4
v1.0.9beta5
v1.0.9beta6
v1.0.9beta7
v1.0.9beta8
v1.0.9beta9
v1.0.9rc1
v1.0.9rc2
v1.00
v1.2.0
v1.2.0beta1
v1.2.0beta2
v1.2.0beta3
v1.2.0beta4
v1.2.0beta5
v1.2.0rc1
v1.2.1
v1.2.10beta1
v1.2.10beta2
v1.2.10beta3
v1.2.10beta4
v1.2.10beta5
v1.2.10beta6
v1.2.10beta7
v1.2.10rc1
v1.2.1beta1
v1.2.1beta2
v1.2.1beta3
v1.2.1beta4
v1.2.1rc1
v1.2.1rc2
v1.2.2
v1.2.2beta1
v1.2.2beta2
v1.2.2beta3
v1.2.2beta4
v1.2.2beta5
v1.2.2beta6
v1.2.2rc1
v1.2.3
v1.2.3rc1
v1.2.3rc2
v1.2.3rc3
v1.2.3rc4
v1.2.3rc5
v1.2.3rc6
v1.2.4
v1.2.4beta1
v1.2.4beta2
v1.2.4beta3
v1.2.4rc1
v1.2.5
v1.2.5beta1
v1.2.5beta2
v1.2.5rc1
v1.2.5rc2
v1.2.5rc3
v1.2.6
v1.2.6beta1
v1.2.6beta2
v1.2.6beta3
v1.2.6beta4
v1.2.6rc1
v1.2.6rc2
v1.2.6rc3
v1.2.6rc4
v1.2.6rc5
v1.2.7
v1.2.7beta1
v1.2.7beta2
v1.2.7rc1
v1.2.8
v1.2.8beta1
v1.2.8beta2
v1.2.8beta3
v1.2.8beta4
v1.2.8beta5
v1.2.8rc1
v1.2.8rc2
v1.2.8rc3
v1.2.8rc4
v1.2.8rc5
v1.2.9
v1.2.9beta1
v1.2.9beta10
v1.2.9beta11
v1.2.9beta2
v1.2.9beta3
v1.2.9beta4
v1.2.9beta5
v1.2.9beta6
v1.2.9beta7
v1.2.9beta8
v1.2.9beta9
v1.2.9rc1
v1.4.0beta1
v1.4.0beta10
v1.4.0beta100
v1.4.0beta101
v1.4.0beta102
v1.4.0beta104
v1.4.0beta105
v1.4.0beta106
v1.4.0beta107
v1.4.0beta108
v1.4.0beta109
v1.4.0beta11
v1.4.0beta12
v1.4.0beta13
v1.4.0beta14
v1.4.0beta15
v1.4.0beta16
v1.4.0beta17
v1.4.0beta18
v1.4.0beta19
v1.4.0beta2
v1.4.0beta20
v1.4.0beta21
v1.4.0beta22
v1.4.0beta23
v1.4.0beta24
v1.4.0beta25
v1.4.0beta26
v1.4.0beta27
v1.4.0beta28
v1.4.0beta29
v1.4.0beta3
v1.4.0beta30
v1.4.0beta31
v1.4.0beta32
v1.4.0beta33
v1.4.0beta34
v1.4.0beta35
v1.4.0beta36
v1.4.0beta37
v1.4.0beta38
v1.4.0beta39
v1.4.0beta4
v1.4.0beta40
v1.4.0beta41
v1.4.0beta42
v1.4.0beta43
v1.4.0beta44
v1.4.0beta45
v1.4.0beta46
v1.4.0beta47
v1.4.0beta48
v1.4.0beta49
v1.4.0beta5
v1.4.0beta50
v1.4.0beta51
v1.4.0beta52
v1.4.0beta53
v1.4.0beta54
v1.4.0beta55
v1.4.0beta56
v1.4.0beta57
v1.4.0beta58
v1.4.0beta6
v1.4.0beta60
v1.4.0beta61
v1.4.0beta62
v1.4.0beta63
v1.4.0beta64
v1.4.0beta65
v1.4.0beta66
v1.4.0beta67
v1.4.0beta68
v1.4.0beta69
v1.4.0beta7
v1.4.0beta70
v1.4.0beta71
v1.4.0beta73
v1.4.0beta75
v1.4.0beta76
v1.4.0beta77
v1.4.0beta78
v1.4.0beta79
v1.4.0beta8
v1.4.0beta80
v1.4.0beta81
v1.4.0beta82
v1.4.0beta83
v1.4.0beta84
v1.4.0beta85
v1.4.0beta86
v1.4.0beta87
v1.4.0beta89
v1.4.0beta9
v1.4.0beta90
v1.4.0beta91
v1.4.0beta92
v1.4.0beta93
v1.4.0beta94
v1.4.0beta95
v1.4.0beta96
v1.4.0beta98
v1.4.0beta99
v1.4.0rc03
v1.4.0rc04
v1.4.0rc05
v1.4.0rc06
v1.4.0rc07
v1.4.0rc08
v1.5.0
v1.5.0beta01
v1.5.0beta02
v1.5.0beta03
v1.5.0beta04
v1.5.0beta05
v1.5.0beta06
v1.5.0beta07
v1.5.0beta08
v1.5.0beta09
v1.5.0beta11
v1.5.0beta12
v1.5.0beta13
v1.5.0beta14
v1.5.0beta15
v1.5.0beta16
v1.5.0beta17
v1.5.0beta18
v1.5.0beta19
v1.5.0beta20
v1.5.0beta21
v1.5.0beta22
v1.5.0beta23
v1.5.0beta24
v1.5.0beta25
v1.5.0beta26
v1.5.0beta27
v1.5.0beta28
v1.5.0beta29
v1.5.0beta30
v1.5.0beta31
v1.5.0beta32
v1.5.0beta33
v1.5.0beta34
v1.5.0beta35
v1.5.0beta36
v1.5.0beta37
v1.5.0beta38
v1.5.0beta39
v1.5.0beta40
v1.5.0beta41
v1.5.0beta42
v1.5.0beta43
v1.5.0beta44
v1.5.0beta45
v1.5.0beta46
v1.5.0beta47
v1.5.0beta48
v1.5.0beta49
v1.5.0beta50
v1.5.0beta51
v1.5.0beta52
v1.5.0beta53
v1.5.0beta54
v1.5.0beta55
v1.5.0beta56
v1.5.0beta57
v1.5.0beta58
v1.5.0rc01
v1.5.0rc02
v1.5.0rc03
v1.5.0rc05
v1.5.0rc06
v1.5.1
v1.5.10
v1.5.10beta01
v1.5.10beta02
v1.5.10beta03
v1.5.10beta04
v1.5.10rc01
v1.5.11
v1.5.11beta01
v1.5.12
v1.5.13
v1.5.13rc01
v1.5.14
v1.5.14beta02
v1.5.14rc01
v1.5.14rc03
v1.5.15
v1.5.15beta01
v1.5.15beta02
v1.5.15beta04
v1.5.15beta05
v1.5.15beta06
v1.5.15beta07
v1.5.15beta08
v1.5.15beta09
v1.5.15rc01
v1.5.16
v1.5.16beta01
v1.5.16beta02
v1.5.16beta03
v1.5.16beta04
v1.5.16beta05
v1.5.16beta06
v1.5.16rc01
v1.5.17
v1.5.17beta01
v1.5.17rc01
v1.5.17rc02
v1.5.17rc03
v1.5.18
v1.5.18beta01
v1.5.18beta02
v1.5.18beta03
v1.5.18beta04
v1.5.18beta05
v1.5.18rc01
v1.5.18rc02
v1.5.19
v1.5.19beta01
v1.5.19beta02
v1.5.19beta03
v1.5.19beta04
v1.5.19beta05
v1.5.19rc01
v1.5.1beta01
v1.5.1beta02
v1.5.1beta03
v1.5.1beta04
v1.5.1beta05
v1.5.1beta06
v1.5.1beta07
v1.5.1beta08
v1.5.1beta09
v1.5.1beta10
v1.5.1beta11
v1.5.1rc01
v1.5.1rc02
v1.5.2
v1.5.20
v1.5.20beta01
v1.5.20rc01
v1.5.20rc02
v1.5.20rc03
v1.5.21
v1.5.21beta01
v1.5.21rc01
v1.5.21rc02
v1.5.21rc03
v1.5.22beta01
v1.5.22beta02
v1.5.22beta03
v1.5.22beta04
v1.5.22rc01
v1.5.22rc02
v1.5.22rc03
v1.5.22rc04
v1.5.2beta01
v1.5.2beta02
v1.5.2beta03
v1.5.2rc01
v1.5.2rc02
v1.5.2rc03
v1.5.3beta01
v1.5.3beta02
v1.5.3beta03
v1.5.3beta05
v1.5.3beta06
v1.5.3beta07
v1.5.3beta08
v1.5.3beta09
v1.5.3beta10
v1.5.3beta11
v1.5.3rc01
v1.5.3rc02
v1.5.4
v1.5.4beta01
v1.5.4beta02
v1.5.4beta03
v1.5.4beta04
v1.5.4beta05
v1.5.4beta06
v1.5.4beta07
v1.5.4beta08
v1.5.4rc01
v1.5.5
v1.5.5beta01
v1.5.5beta02
v1.5.5beta03
v1.5.5beta04
v1.5.5beta05
v1.5.5beta06
v1.5.5beta07
v1.5.5beta08
v1.5.5rc01
v1.5.6
v1.5.6beta01
v1.5.6beta02
v1.5.6beta03
v1.5.6beta04
v1.5.6beta05
v1.5.6beta06
v1.5.6beta07
v1.5.6rc01
v1.5.6rc02
v1.5.6rc03
v1.5.7
v1.5.7beta01
v1.5.7beta02
v1.5.7beta03
v1.5.7beta04
v1.5.7beta05
v1.5.7rc01
v1.5.7rc02
v1.5.7rc03
v1.5.8beta01
v1.5.8rc02
v1.5.9
v1.5.9beta01
v1.5.9rc01

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14822.json"
vanir_signatures
[
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/pnggroup/libpng/commit/4b1b9ce0285b541f1af8a88a2496e06c5c7c25c7",
        "digest": {
            "line_hashes": [
                "90761546293374244527845917547018530649",
                "137417495245102076830839418912487002875",
                "86992279080513503103041527767894422514",
                "26202202500714731688447689440888618643",
                "329693854444850826831444906273737298145",
                "17011134855486730718262056536851411265",
                "83512374228937042689883712080376059557",
                "136955984917707785624811019298884841478",
                "135789412668193218260238724448674301482",
                "250271634670548667808231911998195485587",
                "21548005462996977272692476291400760561",
                "5721070315593613140786678524936315593",
                "290847783886619613480341592952948273327",
                "290075448502179123271977928512358801069",
                "188659470340039086293285886598503408905",
                "169386802321460230450472092086986617968",
                "66334212622631860291524007319082683391"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2019-14822-08668ea7",
        "deprecated": false,
        "target": {
            "file": "png.c"
        }
    },
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/pnggroup/libpng/commit/4b1b9ce0285b541f1af8a88a2496e06c5c7c25c7",
        "digest": {
            "line_hashes": [
                "103641275533327891742404614660718038032",
                "79756851402468988080339013805614573032"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2019-14822-0e0c26b7",
        "deprecated": false,
        "target": {
            "file": "pngtest.c"
        }
    },
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/pnggroup/libpng/commit/4b1b9ce0285b541f1af8a88a2496e06c5c7c25c7",
        "digest": {
            "line_hashes": [
                "319446082283397417357292147670114060718"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2019-14822-3cc451fd",
        "deprecated": false,
        "target": {
            "file": "scripts/def.c"
        }
    },
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/pnggroup/libpng/commit/4b1b9ce0285b541f1af8a88a2496e06c5c7c25c7",
        "digest": {
            "function_hash": "248162538238179664623997276981225140387",
            "length": 669.0
        },
        "id": "CVE-2019-14822-5e4a066b",
        "deprecated": false,
        "target": {
            "file": "png.c",
            "function": "png_get_copyright"
        }
    },
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/pnggroup/libpng/commit/4b1b9ce0285b541f1af8a88a2496e06c5c7c25c7",
        "digest": {
            "line_hashes": [
                "6771525973491036040084693724922220016",
                "195508185938392100944718530499581517082",
                "275647010778297936193963675511576832388",
                "256826767335212246520616614652191899280",
                "279336807821086835335477021495116274772",
                "277530601395564456060893550767859402611",
                "214498808824403563264746917551340068785",
                "165725701263494797958230878374140705547",
                "20809997950832724462152988439710275236"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2019-14822-bfdad6b3",
        "deprecated": false,
        "target": {
            "file": "png.h"
        }
    }
]