KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade kauth | Jul 30, 2024 | May 7, 2019 |
| Freebsd | — | Upgrade kf5-kauth | Feb 11, 2019 | Feb 10, 2019 |
| Suse | — | Upgrade kauth-devel-32bitUpgrade libKF5Auth5-64bitUpgrade kcoreaddons-langUpgrade libKF5CoreAddons5-64bitUpgrade libpolkit-qt5-1-devel-64bitUpgrade libKF5Auth5-langUpgrade kauth-devel-64bitUpgrade libpolkit-qt5-1-1-64bitUpgrade kcoreaddons-devel-64bitUpgrade libKF5Auth5Upgrade extra-cmake-modulesUpgrade libpolkit-qt5-1-develUpgrade kauth-develUpgrade libKF5CoreAddons5Upgrade kcoreaddons-develUpgrade kcoreaddonsUpgrade libKF5Auth5-32bitUpgrade libpolkit-qt5-1-1 | Feb 27, 2019 | Feb 9, 2019 |
| Ubuntu | — | Upgrade libkf5auth-data (Ubuntu Pro)Upgrade libkf5auth5 (Ubuntu Pro) | Apr 21, 2023 | May 7, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub