USN-608-1: KDE vulnerability
===========================================================
Ubuntu Security Notice USN-608-1 May 06, 2008
kdelibs vulnerability
CVE-2008-1671
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 7.04
Ubuntu 7.10
Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 7.04:
kdelibs4c2a 4:3.5.6-0ubuntu14.3
Ubuntu 7.10:
kdelibs4c2a 4:3.5.8-0ubuntu3.4
Ubuntu 8.04 LTS:
kdelibs4c2a 4:3.5.9-0ubuntu7.1
After a standard system upgrade you need to restart your session to effect
the necessary changes.
Details follow:
It was discovered that start_kdeinit in KDE 3 did not properly sanitize
its input. A local attacker could exploit this to send signals to other
processes and cause a denial of service or possibly execute arbitrary
code. (CVE-2008-1671)



