Bug#478024: kdelibs: CVE-2008-1671 start_kdeinit multiple vulnerabilities

2008-04-26 Thread Nico Golde
Hi, I only set the severity to important and did not make this an RC bug as the impact of this is rather low/unimportant. I see no obvious way to exploit the integer overflow here that results in code execution and the only signals that can be sent here are SIGUSR1. Cheers Nico -- Nico Golde

Bug#478024: kdelibs: CVE-2008-1671 start_kdeinit multiple vulnerabilities

2008-04-26 Thread Nico Golde
Package: kdelibs Severity: important Tags: security patch Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for kdelibs. CVE-2008-1671[0]: | 1. Systems affected: | | start_kdeinit of KDE 3.x as of KDE 3.5.5 or newer. KDE 4.0 | and newer is not affected. Only Li