7.2
CVSSv2

CVE-2020-27187

Published: 26/10/2020 Updated: 28/04/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in KDE Partition Manager 4.1.0 prior to 4.2.0. The kpmcore_externalcommand helper contains a logic flaw in which the service invoking D-Bus is not properly checked. An attacker on the local machine can replace /etc/fstab, and execute mount and other partitioning related commands, while KDE Partition Manager is running. the mount command can then be used to gain full root privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kde partition manager

Vendor Advisories

kpmcore_externalcommand helper contains a logic flaw in which the service invoking dbus is not properly checked An attacker on your local machine can replace /etc/fstab, execute mount and other partitioning related commands while KDE Partition Manager is running mount command can then be used to gain full root privileges ...