Vulnerability Name:

CVE-2008-1671 (CCN-42039)

Assigned:2008-04-26
Published:2008-04-26
Updated:2017-08-08
Summary:start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service and possibly execute arbitrary code via "user-influenceable input" (probably command-line arguments) that cause start_kdeinit to send SIGUSR1 signals to other processes.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-16
Vulnerability Consequences:Gain Privileges
References:Source: CONFIRM
Type: Exploit
ftp://ftp.kde.org/pub/kde/security_patches/post-kde-3.5.5-kinit.diff

Source: MITRE
Type: CNA
CVE-2008-1671

Source: SUSE
Type: UNKNOWN
SUSE-SR:2008:011

Source: CCN
Type: SA29951
KDE start_kdeinit Privilege Escalation Vulnerability

Source: SECUNIA
Type: Vendor Advisory
29951

Source: SECUNIA
Type: UNKNOWN
29977

Source: SECUNIA
Type: UNKNOWN
30113

Source: GENTOO
Type: UNKNOWN
GLSA-200804-30

Source: CCN
Type: SECTRACK ID: 1019924
KDE start_kdeinit Input Validation Flaw May Let Local Users Gain Elevated Privileges

Source: CCN
Type: GLSA-200804-30
KDE start_kdeinit: Multiple vulnerabilities

Source: CCN
Type: KDE Security Advisory 2008-04-26
start_kdeinit multiple vulnerabilities

Source: CONFIRM
Type: UNKNOWN
http://www.kde.org/info/security/advisory-20080426-2.txt

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2008:097

Source: CCN
Type: OSVDB ID: 44631
KDE start_kdeinit Local Privilege Escalation

Source: BID
Type: UNKNOWN
28938

Source: CCN
Type: BID-28938
KDE 'start_kdeinit' Multiple Local Privilege Escalation Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1019924

Source: CCN
Type: USN-608-1
KDE vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-608-1

Source: VUPEN
Type: UNKNOWN
ADV-2008-1370

Source: XF
Type: UNKNOWN
kde-startkdeinit-privilege-escalation(42039)

Source: XF
Type: UNKNOWN
kde-startkdeinit-privilege-escalation(42039)

Source: SUSE
Type: SUSE-SR:2008:011
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/o:kde:kde:3.5.5:*:*:*:*:*:*:*
  • OR cpe:/o:kde:kde:3.5.6:*:*:*:*:*:*:*
  • OR cpe:/o:kde:kde:3.5.7:*:*:*:*:*:*:*
  • OR cpe:/o:kde:kde:3.5.8:*:*:*:*:*:*:*
  • OR cpe:/o:kde:kde:3.5.9:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:kde:kde:3.5.5:*:*:*:*:*:*:*
  • OR cpe:/o:kde:kde:3.5.6:*:*:*:*:*:*:*
  • OR cpe:/o:kde:kde:3.5.7:*:*:*:*:*:*:*
  • OR cpe:/o:kde:kde:3.5.8:*:*:*:*:*:*:*
  • OR cpe:/o:kde:kde:3.5.9:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:7.04:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:7.10:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:x86_64:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:8.04::lts:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20081671
    V
    CVE-2008-1671
    2022-05-20
    oval:org.opensuse.security:def:42335
    P
    Security update for xen (Important)
    2022-02-04
    oval:org.opensuse.security:def:31754
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:32236
    P
    Security update for MozillaFirefox (Important)
    2021-12-12
    oval:org.opensuse.security:def:26179
    P
    Security update for gmp (Moderate)
    2021-12-02
    oval:org.opensuse.security:def:31712
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:31705
    P
    Security update for postgresql, postgresql13, postgresql14 (Important)
    2021-11-20
    oval:org.opensuse.security:def:32215
    P
    Security update for qemu (Important)
    2021-11-10
    oval:org.opensuse.security:def:42132
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:31279
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:26135
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:32171
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:31257
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:26108
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:32149
    P
    Security update for linuxptp (Important)
    2021-07-21
    oval:org.opensuse.security:def:31647
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:31205
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-06-18
    oval:org.opensuse.security:def:31638
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:36426
    P
    kdelibs3-32bit-3.5.10-23.27.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42567
    P
    kdelibs3-3.5.10-23.27.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:31193
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:31194
    P
    Security update for qemu (Important)
    2021-06-08
    oval:org.opensuse.security:def:36160
    P
    kdelibs3-3.5.10-23.27.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32110
    P
    Security update for gstreamer-plugins-bad (Important)
    2021-06-07
    oval:org.opensuse.security:def:31627
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:26055
    P
    Security update for hivex (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:26052
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:26051
    P
    Security update for djvulibre (Important)
    2021-05-19
    oval:org.opensuse.security:def:31613
    P
    Security update for tomcat (Important)
    2021-04-29
    oval:org.opensuse.security:def:32080
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:32892
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:32061
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:31349
    P
    Security update for MozillaFirefox (Important)
    2021-03-01
    oval:org.opensuse.security:def:33084
    P
    Security update for tomcat (Moderate)
    2021-02-25
    oval:org.opensuse.security:def:26196
    P
    Security update for ImageMagick (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:26157
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:31649
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:26210
    P
    Security update for MozillaFirefox (Important)
    2021-01-12
    oval:org.opensuse.security:def:31626
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:25976
    P
    Security update for curl (Moderate)
    2020-12-10
    oval:org.opensuse.security:def:25975
    P
    Security update for openssl-1_0_0 (Important)
    2020-12-09
    oval:org.opensuse.security:def:32013
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2020-12-07
    oval:org.opensuse.security:def:32005
    P
    Security update for xen (Important)
    2020-12-07
    oval:org.opensuse.security:def:31560
    P
    Security update for python-cryptography (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:35571
    P
    kdelibs3-3.5.10-23.27.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35725
    P
    kdelibs3-3.5.10-23.27.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:41978
    P
    kdelibs3-3.5.10-23.27.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35928
    P
    kdelibs3-3.5.10-23.27.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25288
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31503
    P
    Security update for python27 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26339
    P
    Security update for openjpeg2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25710
    P
    Security update for log4j (Important)
    2020-12-01
    oval:org.opensuse.security:def:31844
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:26441
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31039
    P
    Security update for kdelibs3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25480
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31849
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:31793
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26927
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25785
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25548
    P
    Security update for ceph (Important)
    2020-12-01
    oval:org.opensuse.security:def:31908
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27389
    P
    derby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31051
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25618
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:32292
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31396
    P
    Security update for perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25994
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25752
    P
    Security update for libreoffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25123
    P
    Security update for ucode-intel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25854
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32690
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25478
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31481
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26401
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25198
    P
    Security update for perl (Important)
    2020-12-01
    oval:org.opensuse.security:def:26388
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26690
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25490
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26605
    P
    libtiff3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26254
    P
    Security update for dia (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25407
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:31803
    P
    Security update for amanda (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26707
    P
    glib2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25682
    P
    Security update for wpa_supplicant (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31947
    P
    Security update for gpg2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27158
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25702
    P
    Security update for libvpx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32497
    P
    cron on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25820
    P
    Security update for xerces-c (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25801
    P
    Security update for libvdpau (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26260
    P
    Security update for Mesa (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25906
    P
    Security update for sane-backends (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32402
    P
    Security update for vim (Important)
    2020-12-01
    oval:org.opensuse.security:def:25277
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:31411
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26286
    P
    Security update for libcdio (Low)
    2020-12-01
    oval:org.opensuse.security:def:26008
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25709
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31493
    P
    Security update for python
    2020-12-01
    oval:org.opensuse.security:def:26427
    P
    Security update for python-Django (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26571
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25352
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:31762
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26654
    P
    xpdf-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26892
    P
    expat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25721
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31936
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:31859
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26485
    P
    Security update for singularity (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31040
    P
    Security update for kdelibs4
    2020-12-01
    oval:org.opensuse.security:def:25561
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:31815
    P
    Security update for apache2-mod_perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31395
    P
    Security update for perl
    2020-12-01
    oval:org.opensuse.security:def:25913
    P
    Security update for tcpdump, libpcap (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25699
    P
    Security update for dnsmasq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27424
    P
    kdelibs3-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25122
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:31125
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25904
    P
    Security update for gegl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32341
    P
    Security update for spice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32651
    P
    dhcpcd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31407
    P
    Security update for perl-XML-LibXML (Important)
    2020-12-01
    oval:org.opensuse.security:def:26317
    P
    Security update for chromium (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25955
    P
    Security update for gstreamer-0_10-plugins-bad (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32446
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:25134
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25898
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25479
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26552
    P
    g3utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33123
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25326
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:26693
    P
    evolution-data-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26725
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25554
    P
    Security update for unzip (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31993
    P
    Security update for java-1_7_1-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27123
    P
    file-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25987
    P
    Security update for the Linux Kernel (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25464
    P
    Security update for java-11-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:26751
    P
    libltdl7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25763
    P
    Security Update for Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31969
    P
    Security update for ipsec-tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25853
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32380
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32536
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25276
    P
    Security update for openssl-1_1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25840
    P
    Security update for libvirt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32853
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31406
    P
    Security update for perl-PlRPC (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26536
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:17614
    P
    USN-608-1 -- kdelibs vulnerability
    2014-06-30
    BACK
    kde kde 3.5.5
    kde kde 3.5.6
    kde kde 3.5.7
    kde kde 3.5.8
    kde kde 3.5.9
    kde kde 3.5.5
    kde kde 3.5.6
    kde kde 3.5.7
    kde kde 3.5.8
    kde kde 3.5.9
    gentoo linux *
    mandrakesoft mandrake linux 2008.0
    canonical ubuntu 7.04
    canonical ubuntu 7.10
    mandrakesoft mandrake linux 2008.0
    mandrakesoft mandrake linux 2008.1 x86_64
    mandrakesoft mandrake linux 2008.1
    canonical ubuntu 8.04