CVE-2011-5054: Medium severity kde kcheckpass vulnerability
kcheckpass passes a user-supplied argument to the pamstart function, often within a setuid environment, which allows local users to invoke any configured PAM stack, and possibly trigger unintended side effects, via an arbitrary valid PAM service name, a different vulnerability than CVE-2011-4122. NOTE: the vendor indicates that the possibility of resultant privilege escalation may be "a bit far-fetched."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5054?
CVE-2011-5054 is considered to have a medium severity due to its potential for local privilege escalation.
How do I fix CVE-2011-5054?
To mitigate CVE-2011-5054, update kcheckpass to a version that has fixed this vulnerability.
Who is affected by CVE-2011-5054?
CVE-2011-5054 affects users of kcheckpass that operate in a setuid environment.
What type of vulnerability is CVE-2011-5054?
CVE-2011-5054 is a local privilege escalation vulnerability.
Can CVE-2011-5054 be exploited remotely?
No, CVE-2011-5054 can only be exploited locally by authenticated users.