KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."
CVSS Details
- CVSS 3.1 Base Score: 7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade polkit-qt-docUpgrade polkit-qtUpgrade polkit-qt-devel | Dec 1, 2016 | Aug 19, 2014 |
| Freebsd | — | Upgrade kdelibs | Dec 10, 2025 | Jul 31, 2014 |
| Oracle_linux | — | Upgrade polkit-qt-develUpgrade polkit-qt-docUpgrade polkit-qt | Oct 16, 2024 | Aug 19, 2014 |
| Suse | — | Upgrade kdelibs4-doc-debuginfoUpgrade libksuseinstall-develUpgrade libkdecore4Upgrade kwinUpgrade kdelibs4-coreUpgrade kwin-debuginfoUpgrade kdebase4-workspace-liboxygenstyleUpgrade kdelibs4-core-debuginfoUpgrade kdebase4-workspace-plasma-calendarUpgrade kdebase4-workspace-plasma-calendar-debuginfoUpgrade libkde4Upgrade libkdecore4-debuginfoUpgrade kdmUpgrade kdelibs4Upgrade kdebase4-workspace-ksysguardd-debuginfoUpgrade kdebase4-workspace-branding-upstreamUpgrade libksuseinstall1-32bitUpgrade kdebase4-workspaceUpgrade krandrUpgrade libkde4-debuginfoUpgrade kdebase4-workspace-develUpgrade kdebase4-workspace-debuginfoUpgrade kde4-kgreeter-pluginsUpgrade libksuseinstall1Upgrade kdebase4-workspace-liboxygenstyle-debuginfo-32bitUpgrade libkdecore4-develUpgrade libksuseinstall1-debuginfo-32bitUpgrade libkdecore4-debuginfo-32bitUpgrade kdm-branding-upstreamUpgrade kdelibs4-debuginfoUpgrade kdm-debuginfoUpgrade kde4-kgreeter-plugins-debuginfoUpgrade kdelibs4-apidocsUpgrade python-kdebase4Upgrade kdelibs4-branding-upstreamUpgrade libkde4-debuginfo-32bitUpgrade libkdecore4-32bitUpgrade kdebase4-workspace-ksysguarddUpgrade libkde4-develUpgrade libkdecore4-devel-debuginfoUpgrade libkde4-32bitUpgrade krandr-debuginfoUpgrade kdebase4-workspace-liboxygenstyle-debuginfoUpgrade kdelibs4-debugsourceUpgrade kdebase4-workspace-liboxygenstyle-32bitUpgrade libksuseinstall1-debuginfoUpgrade kdelibs4-docUpgrade kdebase4-workspace-devel-debuginfoUpgrade kdebase4-workspace-debugsource | Dec 18, 2015 | Aug 11, 2014 |
| Ubuntu | — | Upgrade kdelibs5-plugins | Nov 8, 2024 | Aug 19, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub