CVE-2014-8651
published 2014-12-06CVE-2014-8651: The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted…
PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.39%
31.6th percentile
The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| kde | kde-workspace | <= 4.11.13 | — |
| kde | kde-workspace | >= 0 < 4:4.11.11-0ubuntu0.2 | 4:4.11.11-0ubuntu0.2 |
| kde | plasma-desktop | <= 5.1 | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
KDE workspace vulnerability
vendor_ubuntu·2014-11-11
CVE-2014-8651 KDE workspace vulnerability
Title: KDE workspace vulnerability
Summary: KDE workspace could be made to crash or run programs as an administrator.
David Edmundson discovered that the KDE Clock KCM policykit helper did not
properly guard against untrusted input. Under certain circumstances, a
process running under the user's session could exploit this to run
programs as the administrator.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
kde-workspace: arbitrary code execution and local privilege escalation
vendor_redhat·2014-11-04·CVSS 7.2
CVE-2014-8651 [HIGH] CWE-78 kde-workspace: arbitrary code execution and local privilege escalation
kde-workspace: arbitrary code execution and local privilege escalation
The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.
Mitigation: Add a polkit rule to disable the org.kde.kcontrol.kcmclock.save action. This rule can be tweaked by configuring file /usr/share/polkit-1/actions/org.kde.kcontrol.kcmclock.policy
no = NOT AUTHORIZED for inactive sessions
no
auth_admin = Administration Authorization is Required to perform such action. Change this to 'no'
no
Package: kde-workspace (Red Hat Enterprise Linux 7) - Will not fix
GHSA
GHSA-qpg7-58m4-m59v: The KDE Clock KCM policykit helper in kde-workspace before 4
ghsa_unreviewed·2022-05-17
CVE-2014-8651 [HIGH] GHSA-qpg7-58m4-m59v: The KDE Clock KCM policykit helper in kde-workspace before 4
The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.
OSV
CVE-2014-8651: The KDE Clock KCM policykit helper in kde-workspace before 4
osv·2014-11-07·CVSS 7.2
CVE-2014-8651 [HIGH] CVE-2014-8651: The KDE Clock KCM policykit helper in kde-workspace before 4
The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2014-November/143781.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-November/144034.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-November/144093.htmlhttp://www.openwall.com/lists/oss-security/2014/11/04/9http://www.openwall.com/lists/oss-security/2014/11/07/3http://www.securityfocus.com/bid/70904http://www.ubuntu.com/usn/USN-2402-1https://security.gentoo.org/glsa/201512-12https://www.kde.org/info/security/advisory-20141106-1.txthttp://lists.fedoraproject.org/pipermail/package-announce/2014-November/143781.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-November/144034.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-November/144093.htmlhttp://www.openwall.com/lists/oss-security/2014/11/04/9http://www.openwall.com/lists/oss-security/2014/11/07/3http://www.securityfocus.com/bid/70904http://www.ubuntu.com/usn/USN-2402-1https://security.gentoo.org/glsa/201512-12https://www.kde.org/info/security/advisory-20141106-1.txt
2014-12-06
Published