Submitted by KeesCook on Wed, 2005-09-07 12:03
Referenced CVEs:
CAN-2005-2494
Description:
===========================================================
Ubuntu Security Notice USN-176-1 September 07, 2005
kdebase vulnerability
CAN-2005-2494
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.04 (Hoary Hedgehog)
The following packages are affected:
kdebase-bin
The problem can be corrected by upgrading the affected package to
version 4:3.4.0-0ubuntu18.1. In general, a standard system upgrade is
sufficient to effect the necessary changes.
Details follow:
Ilja van Sprundel discovered a flaw in the lock file handling of
kcheckpass. A local attacker could exploit this to execute arbitrary
code with root privileges.


