============================================================================ Ubuntu Security Notice USN-2402-1 November 11, 2014 kde-workspace vulnerabilities ============================================================================ A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: KDE workspace could be made to crash or run programs as an administrator. Software Description: - kde-workspace: KDE Plasma Workspace components Details: David Edmundson discovered that the KDE Clock KCM policykit helper did not properly guard against untrusted input. Under certain circumstances, a process running under the user's session could exploit this to run programs as the administrator. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: kde-workspace-bin 4:4.8.5-0ubuntu0.4 In general, a standard system update will make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2402-1 CVE-2014-8651 Package Information: https://launchpad.net/ubuntu/+source/kde-workspace/4:4.8.5-0ubuntu0.4