PT-2024-10421 · Kde+4 · Kde Plasma Workspace+4

Fabian Vogt

·

Published

2024-04-14

·

Updated

2024-08-18

·

CVE-2024-36041

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KDE Plasma Workspace versions prior to 5.27.11.1 KDE Plasma Workspace 6.x versions prior to 6.0.5.1
Description The issue allows connections via ICE based purely on the host, i.e., all local connections are accepted. This enables another user on the same machine to gain access to the session manager. A well-crafted client could use the session restore feature to execute arbitrary code as the victim on the next boot via earlier use of the /tmp directory.
Recommendations For KDE Plasma Workspace versions prior to 5.27.11.1, update to version 5.27.11.1 or later. For KDE Plasma Workspace 6.x versions prior to 6.0.5.1, update to version 6.0.5.1 or later. As a temporary workaround, consider restricting access to the session manager to minimize the risk of exploitation.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-8795
ALT-PU-2024-9141
BDU:2025-00953
CVE-2024-36041
DLA-3827-1
DSA-5723-1
MGASA-2024-0214
OESA-2024-1937
OPENSUSE-SU-2024:0161-1
OPENSUSE-SU-2024:14018-1
USN-6843-1

Affected Products

Alt Linux
Astra Linux
Kde Plasma Workspace
Linuxmint
Ubuntu