LWN.net Logo

kdelibs: arbitrary code execution

Package(s):kdelibs CVE #(s):CVE-2008-1671
Created:April 28, 2008 Updated:May 9, 2008
Description:

From the KDE advisory:

start_kdeinit is a wrapper to launch kdeinit with a lower OOM score on Linux. This helper is used to ensure that a single KDE application triggering the Linux kernel OOM killer does not kill the whole KDE session. By default, start_kdeinit is installed as setuid root. The start_kdeinit processing of user-influenceable input is faulty.

If start_kdeinit is installed as setuid root, a local user might be able to send unix signals to other processes, cause a denial of service or even possibly execute arbitrary code.

Alerts:
SuSE SUSE-SR:2008:011 2008-05-09
Ubuntu USN-608-1 2008-05-06
Slackware SSA:2008-116-01 2008-04-28
Mandriva MDVSA-2008:097 2008-05-06
Gentoo 200804-30 2008-04-29

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds