KDE workspace configuration module for setting the date and time has a
helper program which runs as root for performing actions. This is
secured with polkit. This helper takes the name of the ntp utility to
run as an argument. This allows a hacker to run any arbitrary command as
root under the guise of updating the time.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
any | any | any | kdebase-workspace | < 4.11.13-2 | UNKNOWN |