Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gh63-q3pg-7q7r

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

EPSS

Процентиль: 8%
0.00034
Низкий

Дефекты

CWE-362

Связанные уязвимости

ubuntu
около 11 лет назад

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

redhat
больше 11 лет назад

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

nvd
около 11 лет назад

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

debian
около 11 лет назад

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-B ...

oracle-oval
почти 11 лет назад

ELSA-2014-1359: polkit-qt security update (IMPORTANT)

EPSS

Процентиль: 8%
0.00034
Низкий

Дефекты

CWE-362