First published: Sat Dec 06 2014(Updated: )
The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE Plasma Desktop | <=5.1 | |
KDE Plasma Workspace | <=4.11.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8651 has a severity level of high due to its potential to allow local users to gain elevated privileges.
To fix CVE-2014-8651, update kde-workspace to version 4.11.14 or later and plasma-desktop to version 5.1.1 or later.
CVE-2014-8651 affects users of KDE Plasma Desktop versions prior to 5.1.1 and KDE Plasma Workspace versions prior to 4.11.14.
CVE-2014-8651 allows local attackers to exploit a crafted ntpUtility argument to escalate their privileges.
There are no known workarounds for CVE-2014-8651 other than applying the appropriate software updates.