CVE-2014-5033
Publication date 23 July 2014
Last updated 24 July 2024
Ubuntu priority
KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."
Status
Package | Ubuntu Release | Status |
---|---|---|
kde4libs | 14.04 LTS trusty |
Fixed 4:4.13.2a-0ubuntu0.3
|
Patch details
Package | Patch details |
---|---|
kde4libs |
References
Related Ubuntu Security Notices (USN)
- USN-2304-1
- KDE-Libs vulnerability
- 31 July 2014