CVE-2017-8422

KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kde:kauth:*:*:*:*:*:*:*:*
cpe:2.3:a:kde:kdelibs:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:34

Type Values Removed Values Added
References () http://www.debian.org/security/2017/dsa-3849 - () http://www.debian.org/security/2017/dsa-3849 -
References () http://www.openwall.com/lists/oss-security/2017/05/10/3 - Third Party Advisory, VDB Entry () http://www.openwall.com/lists/oss-security/2017/05/10/3 - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/98412 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/98412 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1038480 - () http://www.securitytracker.com/id/1038480 -
References () https://access.redhat.com/errata/RHSA-2017:1264 - () https://access.redhat.com/errata/RHSA-2017:1264 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1449647 - Issue Tracking, Patch () https://bugzilla.redhat.com/show_bug.cgi?id=1449647 - Issue Tracking, Patch
References () https://cgit.kde.org/kauth.git/commit/?id=df875f725293af53399f5146362eb158b4f9216a - Patch () https://cgit.kde.org/kauth.git/commit/?id=df875f725293af53399f5146362eb158b4f9216a - Patch
References () https://cgit.kde.org/kdelibs.git/commit/?id=264e97625abe2e0334f97de17f6ffb52582888ab - Patch () https://cgit.kde.org/kdelibs.git/commit/?id=264e97625abe2e0334f97de17f6ffb52582888ab - Patch
References () https://security.gentoo.org/glsa/201706-29 - () https://security.gentoo.org/glsa/201706-29 -
References () https://www.exploit-db.com/exploits/42053/ - () https://www.exploit-db.com/exploits/42053/ -
References () https://www.kde.org/info/security/advisory-20170510-1.txt - Patch, Vendor Advisory () https://www.kde.org/info/security/advisory-20170510-1.txt - Patch, Vendor Advisory

Information

Published : 2017-05-17 14:29

Updated : 2025-04-20 01:37


NVD link : CVE-2017-8422

Mitre link : CVE-2017-8422

CVE.ORG link : CVE-2017-8422


JSON object : View

Products Affected

kde

  • kauth
  • kdelibs
CWE
CWE-290

Authentication Bypass by Spoofing