PT-2008-1130 · Kde · Kdelibs+1

Helmut Grohne

·

Published

2008-04-28

·

Updated

2017-08-08

·

CVE-2008-1671

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions KDE versions 3.5.5 through 3.5.9 kdelibs versions prior to 4.0
Description The issue allows local users to cause a denial of service and possibly execute arbitrary code via user-influenceable input that cause start kdeinit to send SIGUSR1 signals to other processes. Exploitation of the vulnerability may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For KDE versions 3.5.5 through 3.5.9, consider removing the setuid root bit from start kdeinit to prevent exploitation. For kdelibs versions prior to 4.0, update to version 4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the start kdeinit command to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09636
CVE-2008-1671
DSA-1867-1

Affected Products

Kde
Kdelibs