CVE-2017-8422

NameCVE-2017-8422
DescriptionKDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-952-1, DSA-3849-1
NVD severityhigh (attack range: local)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kauth (PTS)buster, sid, stretch5.28.0-2fixed
kde4libs (PTS)wheezy4:4.8.4-4+deb7u1vulnerable
wheezy (security)4:4.8.4-4+deb7u3fixed
jessie4:4.14.2-5+deb8u1vulnerable
jessie (security)4:4.14.2-5+deb8u2fixed
buster, sid, stretch4:4.14.26-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kauthsource(unstable)5.28.0-2high
kde4libssource(unstable)4:4.14.26-2high
kde4libssourcejessie4:4.14.2-5+deb8u2highDSA-3849-1
kde4libssourcewheezy4:4.8.4-4+deb7u3highDLA-952-1

Notes

http://www.openwall.com/lists/oss-security/2017/05/10/3
patch for kauth: https://cgit.kde.org/kauth.git/commit/?id=df875f725293af53399f5146362eb158b4f9216a
patch for kde4libs: https://cgit.kde.org/kdelibs.git/commit/?h=KDE/4.14&id=264e97625abe2e0334f97de17f6ffb52582888ab
https://www.kde.org/info/security/advisory-20170510-1.txt

Search for package or bug name: Reporting problems