CVE-2020-27187
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic flaw in which the service invoking D-Bus is not properly checked. An attacker on the local machine can replace /etc/fstab, and execute mount and other partitioning related commands, while KDE Partition Manager is running. the mount command can then be used to gain full root privileges.
Se detectó un problema en KDE Partition Manager versiones 4.1.0 anteriores a 4.2.0. El asistente kpmcore_externalcommand contiene un fallo lógico en el que el servicio que invoca D-Bus no es apropiadamente comprobado. Un atacante en la máquina local puede reemplazar a /etc/fstab, y ejecutar un montaje y otros comandos relacionados con la partición, mientras KDE Partition Manager se está ejecutando. El comando mount puede entonces ser usado para alcanzar privilegios root completos
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-16 CVE Reserved
- 2020-10-26 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/KDE/partitionmanager/compare/v4.1.0...v4.2.0 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://kde.org/info/security/advisory-20201017-1.txt | 2022-04-28 |
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1890199 | 2022-04-28 | |
https://security.gentoo.org/glsa/202011-03 | 2022-04-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kde Search vendor "Kde" | Partition Manager Search vendor "Kde" for product "Partition Manager" | >= 4.1.0 < 4.2.0 Search vendor "Kde" for product "Partition Manager" and version " >= 4.1.0 < 4.2.0" | - |
Affected
|