4.6
CVSSv2

CVE-2008-1671

Published: 28/04/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

start_kdeinit in KDE 3.5.5 up to and including 3.5.9, when installed setuid root, allows local users to cause a denial of service and possibly execute arbitrary code via "user-influenceable input" (probably command-line arguments) that cause start_kdeinit to send SIGUSR1 signals to other processes.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde 3.5.7

kde kde 3.5.8

kde kde 3.5.5

kde kde 3.5.6

kde kde 3.5.9

Vendor Advisories

It was discovered that start_kdeinit in KDE 3 did not properly sanitize its input A local attacker could exploit this to send signals to other processes and cause a denial of service or possibly execute arbitrary code (CVE-2008-1671) ...