FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

kstars -- exploitable set-user-ID application fliccd

Affected packages
kdeedu < 3.3.2_1

Details

VuXML ID 0512b761-70fb-40d3-9954-aa4565528fa8
Discovery 2005-01-05
Entry 2005-06-17

A KDE Security Advisory explains:

Overview

KStars includes support for the Instrument Neutral Distributed Interface (INDI). The build system of this extra 3rd party software contained an installation hook to install fliccd (part of INDI) as SUID root application.

Erik Sjölund discovered that the code contains several vulnerabilities that allow stack based buffer overflows.

Impact

If the fliccd binary is installed as suid root, it enables root privilege escalation for local users, or, if the daemon is actually running (which it does not by default) and is running as root, remote root privilege escalation.

References

CVE Name CVE-2005-0011
URL http://www.kde.org/info/security/advisory-20050215-1.txt