TROYANOSYVIRUS
Retour aux CVEs

CVE-2014-5033

N/A

Description

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

Details CVE

Score CVSS v3.1N/A
Publie8/19/2014
Derniere modification4/12/2025
Sourcenvd
Observations honeypot0

Produits affectes

canonical:ubuntu_linuxdebian:kde4libskde:kauthkde:kdelibs

Faiblesses (CWE)

CWE-362

References

http://rhn.redhat.com/errata/RHSA-2014-1359.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60385(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60633(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60654(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2014/dsa-3004(af854a3a-2127-422b-91ae-364da2661108)
http://www.kde.org/info/security/advisory-20140730-1.txt(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2304-1(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.