[Bug 1350019] [NEW] CVE-2014-5033: kauth authentication bypass

Felix Geyer debfx-pkg at fobos.de
Tue Jul 29 20:01:44 UTC 2014


*** This bug is a security vulnerability ***

Public security bug reported:

In kauth:
Using the PID for authentication is prone to a PID reuse race condition, and a security issue. 

https://bugzilla.novell.com/show_bug.cgi?id=864716
http://quickgit.kde.org/?p=kdelibs.git&a=commit&h=e4e7b53b71e2659adaf52691d4accc3594203b23

** Affects: kde4libs (Ubuntu)
     Importance: Undecided
         Status: New

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2014-5033

-- 
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to kde4libs in Ubuntu.
https://bugs.launchpad.net/bugs/1350019

Title:
  CVE-2014-5033: kauth authentication bypass

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/kde4libs/+bug/1350019/+subscriptions




More information about the kubuntu-bugs mailing list