Описание
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needed |
| cosmic | ignored | end of life |
| devel | not-affected | 5.98.0-0ubuntu1 |
| disco | ignored | end of life |
| eoan | ignored | end of life |
| esm-apps/bionic | released | 5.44.0-0ubuntu1+esm1 |
| esm-apps/focal | not-affected | 5.68.0-0ubuntu1 |
| esm-apps/jammy | not-affected | 5.92.0 |
| esm-apps/xenial | released | 5.18.0-0ubuntu2+esm1 |
| esm-infra-legacy/trusty | DNE |
Показывать по
EPSS
9.3 Critical
CVSS2
8.1 High
CVSS3
Связанные уязвимости
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.
KDE KAuth before 5.55 allows the passing of parameters with arbitrary ...
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.
EPSS
9.3 Critical
CVSS2
8.1 High
CVSS3