Lucene search

K
cveRedhatCVE-2008-1671
HistoryApr 28, 2008 - 5:05 p.m.

CVE-2008-1671

2008-04-2817:05:00
CWE-16
redhat
web.nvd.nist.gov
32
cve
2008
1671
kde
start_kdeinit
vulnerability
denial of service
arbitrary code
nvd

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

High

EPSS

0

Percentile

10.1%

start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service and possibly execute arbitrary code via β€œuser-influenceable input” (probably command-line arguments) that cause start_kdeinit to send SIGUSR1 signals to other processes.

Affected configurations

Nvd
Node
kdekdeMatch3.5.5
OR
kdekdeMatch3.5.6
OR
kdekdeMatch3.5.7
OR
kdekdeMatch3.5.8
OR
kdekdeMatch3.5.9
VendorProductVersionCPE
kdekde3.5.5cpe:2.3:o:kde:kde:3.5.5:*:*:*:*:*:*:*
kdekde3.5.6cpe:2.3:o:kde:kde:3.5.6:*:*:*:*:*:*:*
kdekde3.5.7cpe:2.3:o:kde:kde:3.5.7:*:*:*:*:*:*:*
kdekde3.5.8cpe:2.3:o:kde:kde:3.5.8:*:*:*:*:*:*:*
kdekde3.5.9cpe:2.3:o:kde:kde:3.5.9:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

High

EPSS

0

Percentile

10.1%