KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade kauth | Jul 30, 2024 | May 7, 2019 |
| Freebsd | — | Upgrade kf5-kauth | Feb 11, 2019 | Feb 10, 2019 |
| Suse | — | Upgrade kauth-develUpgrade extra-cmake-modulesUpgrade libpolkit-qt5-1-1Upgrade kcoreaddonsUpgrade libKF5Auth5-32bitUpgrade libpolkit-qt5-1-develUpgrade kcoreaddons-develUpgrade libKF5CoreAddons5Upgrade libKF5Auth5-64bitUpgrade libKF5CoreAddons5-64bitUpgrade kauth-devel-32bitUpgrade kcoreaddons-langUpgrade kcoreaddons-devel-64bitUpgrade libKF5Auth5-langUpgrade libpolkit-qt5-1-1-64bitUpgrade libpolkit-qt5-1-devel-64bitUpgrade libKF5Auth5Upgrade kauth-devel-64bit | Feb 27, 2019 | Feb 9, 2019 |
| Ubuntu | — | Upgrade libkf5auth5 (Ubuntu Pro)Upgrade libkf5auth-data (Ubuntu Pro) | Apr 21, 2023 | May 7, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub