VYPR
High severity7.8NVD Advisory· Published Oct 26, 2020· Updated Jun 17, 2026

CVE-2020-27187

CVE-2020-27187

Description

An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic flaw in which the service invoking D-Bus is not properly checked. An attacker on the local machine can replace /etc/fstab, and execute mount and other partitioning related commands, while KDE Partition Manager is running. the mount command can then be used to gain full root privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:kde:partition_manager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:kde:partition_manager:*:*:*:*:*:*:*:*range: >=4.1.0,<4.2.0
    • (no CPE)range: <4.2.0
  • KDE/Partition Managerdescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.