Unrated severityNVD Advisory· Published Aug 19, 2014· Updated May 6, 2026
CVE-2014-5033
CVE-2014-5033
Description
KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."
Affected products
38cpe:2.3:a:kde:kdelibs:*:*:*:*:*:*:*:*+ 33 more
- cpe:2.3:a:kde:kdelibs:*:*:*:*:*:*:*:*range: <=4.13.97
- cpe:2.3:a:kde:kdelibs:4.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.10.1:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.10.2:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.10.3:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.10.95:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.10.97:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.11.1:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.11.2:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.11.3:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.11.4:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.11.5:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.11.80:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.11.90:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.11.95:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.11.97:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.12.0:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.12.1:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.12.2:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.12.3:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.12.4:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.12.5:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.12.80:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.12.90:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.12.95:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.12.97:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.13.0:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.13.1:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.13.2:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.13.3:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.13.80:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.13.90:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kdelibs:4.13.95:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- quickgit.kde.orgnvdExploitPatch
- www.kde.org/info/security/advisory-20140730-1.txtnvdVendor Advisory
- lists.opensuse.org/opensuse-updates/2014-08/msg00012.htmlnvd
- quickgit.kde.orgnvd
- rhn.redhat.com/errata/RHSA-2014-1359.htmlnvd
- secunia.com/advisories/60385nvd
- secunia.com/advisories/60633nvd
- secunia.com/advisories/60654nvd
- www.debian.org/security/2014/dsa-3004nvd
- www.ubuntu.com/usn/USN-2304-1nvd
News mentions
0No linked articles in our index yet.