CVE-2014-5033

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
VendorProductVersion
debiankde4libs
-
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
kdekauth
𝑥
≤ 5.0
kdekdelibs
𝑥
≤ 4.13.97
kdekdelibs
4.10.0
kdekdelibs
4.10.1
kdekdelibs
4.10.2
kdekdelibs
4.10.3
kdekdelibs
4.10.95
kdekdelibs
4.10.97
kdekdelibs
4.11.0
kdekdelibs
4.11.1
kdekdelibs
4.11.2
kdekdelibs
4.11.3
kdekdelibs
4.11.4
kdekdelibs
4.11.5
kdekdelibs
4.11.80
kdekdelibs
4.11.90
kdekdelibs
4.11.95
kdekdelibs
4.11.97
kdekdelibs
4.12.0
kdekdelibs
4.12.1
kdekdelibs
4.12.2
kdekdelibs
4.12.3
kdekdelibs
4.12.4
kdekdelibs
4.12.5
kdekdelibs
4.12.80
kdekdelibs
4.12.90
kdekdelibs
4.12.95
kdekdelibs
4.12.97
kdekdelibs
4.13.0
kdekdelibs
4.13.1
kdekdelibs
4.13.2
kdekdelibs
4.13.3
kdekdelibs
4.13.80
kdekdelibs
4.13.90
kdekdelibs
4.13.95
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kde4libs
trusty
Fixed 4:4.13.2a-0ubuntu0.3
released
precise
Fixed 4:4.8.5-0ubuntu0.4
released
lucid
ignored