KDE Systemsettings: Privilege escalation Data validation in KDE Systemsettings could lead to local privilege escalation. systemsettings 2015-12-30 2015-12-30 528468 local 4.11.13-r1 4.11.13-r1

KDE workspace configuration module for setting the date and time has a helper program which runs as root for performing actions.

KDE Systemsettings fails to properly validate user input before passing it as argument in context of higher privilege.

A local attacker could gain privileges via a crafted ntpUtility (ntp utility name) argument.

Add a polkit rule to disable the org.kde.kcontrol.kcmclock.save action.

All KDE Systemsettings users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=kde-base/systemsettings-4.11.13-r1"
CVE-2014-8651 Zlogene mrueg