Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Ubuntu 14.04 LTS USN-2304-1 Critical: KDE-Libs Authorization Bypass

Ubuntu Large Esm H500
kauth could be tricked into bypassing polkit authorizations.
=========================================================================Ubuntu Security Notice USN-2304-1
July 31, 2014

kde4libs vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

kauth could be tricked into bypassing polkit authorizations.

Software Description:
- kde4libs: KDE 4 core applications and libraries

Details:

It was discovered that kauth was using polkit in an unsafe manner. A local
attacker could possibly use this issue to bypass intended polkit
authorizations.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  kdelibs5-plugins                4:4.13.2a-0ubuntu0.3

Ubuntu 12.04 LTS:
  kdelibs5-plugins                4:4.8.5-0ubuntu0.4

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2304-1
  CVE-2014-5033

Package Information:
  https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3
  https://launchpad.net/ubuntu/+source/kde4libs/4:4.8.5-0ubuntu0.4


Ubuntu 14.04 LTS USN-2304-1 Critical: KDE-Libs Authorization Bypass

ubuntu
Calendar Grey July 31, 2014
Dist Ubuntu Esm H88
A security flaw in the KDE-Libs allows local adversaries to circumvent polkit permissions on Ubuntu systems. Urgent update instructions issued.
kauth could be tricked into bypassing polkit authorizations.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: kdelibs5-plugins 4:4.13.2a-0ubuntu0.3 Ubuntu 12.04 LTS: kdelibs5-plugins 4:4.8.5-0ubuntu0.4 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2304-1

CVE-2014-5033

Severity
critical
Lowest
Low
Medium
High
Critical

July 31, 2014

Package Information

https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3 https://launchpad.net/ubuntu/+source/kde4libs/4:4.8.5-0ubuntu0.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here