CVE-2014-5033

medium
Published 2014-08-19 · Modified 2026-05-06
CVSS v3
CVSS v2
6.9
VIR risk
6.9

Description

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.kde.org/info/security/advisory-20140730-1.txt

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://quickgit.kde.org/?p=kdelibs.git&a=commitdiff&h=e4e7b53b71e2659adaf52691d4accc3594203b23

OS impact

OSVersionStatusFixed in
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected

Application impact

VendorProductVersionsFixed
debiankde4libs-
kdekauth{"endIncluding":"5.0"}
kdekdelibs{"endIncluding":"4.13.97"}
kdekdelibs4.10.0
kdekdelibs4.10.1
kdekdelibs4.10.2
kdekdelibs4.10.3
kdekdelibs4.10.95
kdekdelibs4.10.97
kdekdelibs4.11.0
kdekdelibs4.11.1
kdekdelibs4.11.2
kdekdelibs4.11.3
kdekdelibs4.11.4
kdekdelibs4.11.5
kdekdelibs4.11.80
kdekdelibs4.11.90
kdekdelibs4.11.95
kdekdelibs4.11.97
kdekdelibs4.12.0
kdekdelibs4.12.1
kdekdelibs4.12.2
kdekdelibs4.12.3
kdekdelibs4.12.4
kdekdelibs4.12.5
kdekdelibs4.12.80
kdekdelibs4.12.90
kdekdelibs4.12.95
kdekdelibs4.12.97
kdekdelibs4.13.0
kdekdelibs4.13.1
kdekdelibs4.13.2
kdekdelibs4.13.3
kdekdelibs4.13.80
kdekdelibs4.13.90
kdekdelibs4.13.95

References

CWEs

CWE-362

Verify integrity in audit chain (admin only). AS-IS.