CVE-2014-5033

medium
Published 2014-08-19 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
6.9

Description

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

ubuntu Ubuntu Affected 2 releases
VersionStatusFixed in
14.04 Affected โ€”
12.04 Affected โ€”

Application impact

VendorProductVersionsFixed
debian debiankde4libs-
kdekauth{"endIncluding":"5.0"}
kdekdelibs{"endIncluding":"4.13.97"}
kdekdelibs4.10.0
kdekdelibs4.10.1
kdekdelibs4.10.2
kdekdelibs4.10.3
kdekdelibs4.10.95
kdekdelibs4.10.97
kdekdelibs4.11.0
kdekdelibs4.11.1
kdekdelibs4.11.2
kdekdelibs4.11.3
kdekdelibs4.11.4
kdekdelibs4.11.5
kdekdelibs4.11.80
kdekdelibs4.11.90
kdekdelibs4.11.95
kdekdelibs4.11.97
kdekdelibs4.12.0
kdekdelibs4.12.1
kdekdelibs4.12.2
kdekdelibs4.12.3
kdekdelibs4.12.4
kdekdelibs4.12.5
kdekdelibs4.12.80
kdekdelibs4.12.90
kdekdelibs4.12.95
kdekdelibs4.12.97
kdekdelibs4.13.0
kdekdelibs4.13.1
kdekdelibs4.13.2
kdekdelibs4.13.3
kdekdelibs4.13.80
kdekdelibs4.13.90
kdekdelibs4.13.95

References

CWEs

CWE-362

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.