CVE-2008-1671

Severity CVSS v4.0:
Pending analysis
Type:
CWE-16 Configuration Errors
Publication date:
28/04/2008
Last modified:
09/04/2025

Description

start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service and possibly execute arbitrary code via "user-influenceable input" (probably command-line arguments) that cause start_kdeinit to send SIGUSR1 signals to other processes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:kde:kde:3.5.5:*:*:*:*:*:*:*
cpe:2.3:o:kde:kde:3.5.6:*:*:*:*:*:*:*
cpe:2.3:o:kde:kde:3.5.7:*:*:*:*:*:*:*
cpe:2.3:o:kde:kde:3.5.8:*:*:*:*:*:*:*
cpe:2.3:o:kde:kde:3.5.9:*:*:*:*:*:*:*