Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-5033


KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."


Published

2014-08-19T18:55:03.233

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.9 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.4

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-362

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application debian kde4libs - Yes
Operating System canonical ubuntu_linux 12.04 Yes
Operating System canonical ubuntu_linux 14.04 Yes
Application kde kauth ≤ 5.0 Yes
Application kde kdelibs ≤ 4.13.97 Yes
Application kde kdelibs 4.10.0 Yes
Application kde kdelibs 4.10.1 Yes
Application kde kdelibs 4.10.2 Yes
Application kde kdelibs 4.10.3 Yes
Application kde kdelibs 4.10.95 Yes
Application kde kdelibs 4.10.97 Yes
Application kde kdelibs 4.11.0 Yes
Application kde kdelibs 4.11.1 Yes
Application kde kdelibs 4.11.2 Yes
Application kde kdelibs 4.11.3 Yes
Application kde kdelibs 4.11.4 Yes
Application kde kdelibs 4.11.5 Yes
Application kde kdelibs 4.11.80 Yes
Application kde kdelibs 4.11.90 Yes
Application kde kdelibs 4.11.95 Yes
Application kde kdelibs 4.11.97 Yes
Application kde kdelibs 4.12.0 Yes
Application kde kdelibs 4.12.1 Yes
Application kde kdelibs 4.12.2 Yes
Application kde kdelibs 4.12.3 Yes
Application kde kdelibs 4.12.4 Yes
Application kde kdelibs 4.12.5 Yes
Application kde kdelibs 4.12.80 Yes
Application kde kdelibs 4.12.90 Yes
Application kde kdelibs 4.12.95 Yes
Application kde kdelibs 4.12.97 Yes
Application kde kdelibs 4.13.0 Yes
Application kde kdelibs 4.13.1 Yes
Application kde kdelibs 4.13.2 Yes
Application kde kdelibs 4.13.3 Yes
Application kde kdelibs 4.13.80 Yes
Application kde kdelibs 4.13.90 Yes
Application kde kdelibs 4.13.95 Yes

References