start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service and possibly execute arbitrary code via "user-influenceable input" (probably command-line arguments) that cause start_kdeinit to send SIGUSR1 signals to other processes.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade kde-base/kdelibs. | Oct 30, 2017 | Apr 28, 2008 |
| Suse | — | Upgrade kdelibs3-develUpgrade kdelibs3Upgrade kdelibs3-x86Upgrade kdelibs3-default-style-x86Upgrade kdelibs3-default-style-32bitUpgrade kdelibs3-arts-x86Upgrade kdelibs3-default-styleUpgrade kdelibs3-32bitUpgrade kdelibs3-docUpgrade kdelibs3-arts-32bitUpgrade kdelibs3-arts | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade kdelibs4c2a | Nov 8, 2024 | Apr 28, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub