Unity8 converged application lifecycle allows background applications to use on-screen keyboard when not top-most
CVE-2016-1584

1.6LOW

Key Information:

Vendor

Ubuntu

Status
Vendor
CVE Published:
22 April 2019

What is CVE-2016-1584?

In all versions of Unity8 a running but not active application on a large-screen device could talk with Maliit and consume keyboard input.

Affected Version(s)

Unity8 all

References

CVSS V3.1

Score:
1.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.