Family: Debian Local Security Checks --> Category: infos
[DSA692] DSA-692-1 kdenetwork Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
The KDE team fixed a bug in kppp in 2002 which was now discovered to be
exploitable by iDEFENSE. By opening a sufficiently large number of
file descriptors before executing kppp which is installed setuid root a
local attacker is able to take over privileged file descriptors.
For the stable distribution (woody) this problem has been fixed in
The testing (sarge) and unstable (sid) distributions are not affected
since KDE 3.2 already contained the correction.
We recommend that you upgrade your kppp package.
Solution : http://www.debian.org/security/2005/dsa-692
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.