Title: KDE KStars FLICCD Utility Multiple Buffer Overflow Vulnerabilities
Severity: CRITICAL
Description:
KDE KStars is a desktop planetarium for KDE. It includes support for the Instrument Neutral Distributed Interface (INDI) functionality; INDI provides an API for device control and automation. The fliccd utility is shipped as part of the INDI support packages, which aids in the INDI support and may be run as a daemon process.
Multiple buffer overflow vulnerabilities affect KDE KStar fliccd. These issues are due to a failure of the utility to securely copy user-supplied data into process memory.
The problems present themselves as the affected utility, fliccd, is installed with setuid superuser privileges. Apparently fliccd is affected by multiple buffer overflow vulnerabilities, allowing a local attacker to exploit the overflow vulnerabilities to gain escalated privileges. Details regarding the buffer overflow issues are currently unavailable; this BID will be updated as more information is released.
It is also reported that if the affected utility is run as a daemon, these issues may facilitate remote exploitation.
An attacker may leverage these issues to gain escalated privileges locally and, if the affected utility is run as a daemon, may facilitate remote code execution with superuser privileges.
Affected Products:
- Debian Linux 3.1.0
- Debian Linux 3.1.0 alpha
- Debian Linux 3.1.0 amd64
- Debian Linux 3.1.0 arm
- Debian Linux 3.1.0 hppa
- Debian Linux 3.1.0 ia-32
- Debian Linux 3.1.0 ia-64
- Debian Linux 3.1.0 m68k
- Debian Linux 3.1.0 mips
- Debian Linux 3.1.0 mipsel
- Debian Linux 3.1.0 ppc
- Debian Linux 3.1.0 s/390
- Debian Linux 3.1.0 sparc
- Gentoo Linux
- KDE KDE 3.3.0
- KDE KDE 3.3.1
- KDE KDE 3.3.2
- RedHat Fedora Core3
References:
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.