KDE start_kdeinit Input Validation Flaw May Let Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1019924
|
|
SecurityTracker URL: http://securitytracker.com/id?1019924
|
|
CVE Reference: CVE-2008-1671
(Links to External Site)
|
Date: Apr 26 2008
|
Impact: Root access via local system, User access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: KDE Security Advisory
|
Version(s): 3.5.5 to 4.0
|
Description: A vulnerability was reported in KDE. A local user may be able to obtain elevated privileges on the target system.
The start_kdeinit wrapper does not properly process user-supplied input. A local user may be able to send UNIX signals to other
processes to cause denial of service conditions or execute arbitrary code.
start_kdeinit is installed with set user id (setuid)
root privileges by default.
|
Impact: A local user may be able to obtain elevated privileges on the target system.
|
Solution: The vendor has issued a patch for KDE 3.5.5 - KDE 3.5.9, available at:
ftp://ftp.kde.org/pub/kde/security_patches
9d99d5f02b696e7a493836f285a319da
post-kde-3.5.5-kinit.diff
The vendor's advisory is available at:
http://www.kde.org/info/security/advisory-20080426-2.txt
|
Vendor URL: www.kde.org/info/security/advisory-20080426-2.txt (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Linux (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Fri, 25 Apr 2008 20:43:58 -0400
Subject: KDE
|
KDE Security Advisory: start_kdeinit multiple vulnerabilities
Original Release Date: 2008-04-26
URL: http://www.kde.org/info/security/advisory-20080426-2.txt
0. References
CVE-2008-1671
1. Systems affected:
start_kdeinit of KDE 3.x as of KDE 3.5.5 or newer. KDE 4.0
and newer is not affected. Only Linux platform is affected.
2. Overview:
start_kdeinit is a wrapper to launch kdeinit with a lower OOM
score on Linux. This helper is used to ensure that a
single KDE application triggering the Linux kernel OOM killer
does not kill the whole KDE session. By default,
start_kdeinit is installed as setuid root. The start_kdeinit
processing of user-influenceable input is faulty.
3. Impact:
If start_kdeinit is installed as setuid root, a local user
might be able to send unix signals to other processes, cause
a denial of service or even possibly execute arbitrary code.
4. Solution:
Source code patches have been made available which fix these
vulnerabilities. Contact your OS vendor / binary package provider
for information about how to obtain updated binary packages.
5. Patch:
A patch for KDE 3.5.5 - KDE 3.5.9 is available from
ftp://ftp.kde.org/pub/kde/security_patches :
9d99d5f02b696e7a493836f285a319da post-kde-3.5.5-kinit.diff
|
|