Back

HIGH

kde-workspace: arbitrary code execution and local privilege escalation

Published Dec 6, 2014

Description

The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.

Affected products

Remediation

Red Hat mitigation

Add a polkit rule to disable the org.kde.kcontrol.kcmclock.save action. This rule can be tweaked by configuring file /usr/share/polkit-1/actions/org.kde.kcontrol.kcmclock.policy no = NOT AUTHORIZED for inactive sessions <allow_inactive>no</allow_inactive> auth_admin = Administration Authorization is Required to perform such action. Change this to 'no' <allow_active>no</allow_active>

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 6, 2014
Updated Aug 6, 2024
Reserved Nov 6, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 4, 2014