TROYANOSYVIRUS
Back to CVEs

CVE-2014-5033

N/A

Description

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

CVE Details

CVSS v3.1 ScoreN/A
Published8/19/2014
Last Modified4/12/2025
Sourcenvd
Honeypot Sightings0

Affected Products

canonical:ubuntu_linuxdebian:kde4libskde:kauthkde:kdelibs

Weaknesses (CWE)

CWE-362

References

http://rhn.redhat.com/errata/RHSA-2014-1359.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60385(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60633(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60654(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2014/dsa-3004(af854a3a-2127-422b-91ae-364da2661108)
http://www.kde.org/info/security/advisory-20140730-1.txt(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2304-1(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.