CVE-2014-5033

EUVD-2014-4932
KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
debiankde4libs
-
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
kdekauth
𝑥
≤ 5.0
kdekdelibs
𝑥
≤ 4.13.97
kdekdelibs
4.10.0
kdekdelibs
4.10.1
kdekdelibs
4.10.2
kdekdelibs
4.10.3
kdekdelibs
4.10.95
kdekdelibs
4.10.97
kdekdelibs
4.11.0
kdekdelibs
4.11.1
kdekdelibs
4.11.2
kdekdelibs
4.11.3
kdekdelibs
4.11.4
kdekdelibs
4.11.5
kdekdelibs
4.11.80
kdekdelibs
4.11.90
kdekdelibs
4.11.95
kdekdelibs
4.11.97
kdekdelibs
4.12.0
kdekdelibs
4.12.1
kdekdelibs
4.12.2
kdekdelibs
4.12.3
kdekdelibs
4.12.4
kdekdelibs
4.12.5
kdekdelibs
4.12.80
kdekdelibs
4.12.90
kdekdelibs
4.12.95
kdekdelibs
4.12.97
kdekdelibs
4.13.0
kdekdelibs
4.13.1
kdekdelibs
4.13.2
kdekdelibs
4.13.3
kdekdelibs
4.13.80
kdekdelibs
4.13.90
kdekdelibs
4.13.95
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kde4libs
lucid
ignored
precise
Fixed 4:4.8.5-0ubuntu0.4
released
trusty
Fixed 4:4.13.2a-0ubuntu0.3
released