CVE-2014-8651OS Command Injection in Kde-workspace

Severity
7.2HIGHNVD
EPSS
0.1%
top 74.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 6
Latest updateMay 17

Description

The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-qpg7-58m4-m59v: The KDE Clock KCM policykit helper in kde-workspace before 42022-05-17
CVEList
CVE-2014-8651: The KDE Clock KCM policykit helper in kde-workspace before 42014-12-06
OSV
CVE-2014-8651: The KDE Clock KCM policykit helper in kde-workspace before 42014-11-07

📋Vendor Advisories

2
Ubuntu
KDE workspace vulnerability2014-11-11
Red Hat
kde-workspace: arbitrary code execution and local privilege escalation2014-11-04

💬Community

1
Bugzilla
CVE-2014-8651 kde-workspace: arbitrary code execution and local privilege escalation2014-11-13
CVE-2014-8651 — OS Command Injection in Kde-workspace | cvebase