CVE-2014-8651: High severity kde plasma desktop vulnerability
The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8651?
CVE-2014-8651 has a severity level of high due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2014-8651?
To fix CVE-2014-8651, update kde-workspace to version 4.11.14 or later and plasma-desktop to version 5.1.1 or later.
Who is affected by CVE-2014-8651?
CVE-2014-8651 affects users of KDE Plasma Desktop versions prior to 5.1.1 and KDE Plasma Workspace versions prior to 4.11.14.
What types of attacks are possible with CVE-2014-8651?
CVE-2014-8651 allows local attackers to exploit a crafted ntpUtility argument to escalate their privileges.
Is there a workaround for CVE-2014-8651?
There are no known workarounds for CVE-2014-8651 other than applying the appropriate software updates.