TROYANOSYVIRUS
Voltar para CVEs

CVE-2014-5033

N/A

Descricao

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado8/19/2014
Ultima modificacao4/12/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

canonical:ubuntu_linuxdebian:kde4libskde:kauthkde:kdelibs

Fraquezas (CWE)

CWE-362

Referencias

http://rhn.redhat.com/errata/RHSA-2014-1359.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60385(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60633(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60654(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2014/dsa-3004(af854a3a-2127-422b-91ae-364da2661108)
http://www.kde.org/info/security/advisory-20140730-1.txt(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2304-1(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.