KDE DCOPServer Local Denial of Service Vulnerability
BID:12820
Info
KDE DCOPServer Local Denial of Service Vulnerability
| Bugtraq ID: | 12820 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-0396 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 16 2005 12:00AM |
| Updated: | Feb 20 2007 09:26PM |
| Credit: | Discovery is credited to Sebastian Krahmer. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 7 SuSE Linux Enterprise Server 9 SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 SGI ProPack 3.0 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Linux 9.0 i386 Redhat Linux 7.3 i386 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 KDE kdelibs 3.3.2 KDE kdelibs 3.3.1 KDE kdelibs 3.3 KDE kdelibs 3.2.2 KDE kdelibs 3.2.1 KDE kdelibs 3.2 KDE KDE 3.3.2 KDE KDE 3.3.1 KDE KDE 3.3 KDE KDE 3.2.3 KDE KDE 3.2.2 KDE KDE 3.2.1 KDE KDE 3.2 KDE KDE 3.1.5 KDE KDE 3.1.4 KDE KDE 3.1.3 KDE KDE 3.1.2 KDE KDE 3.1.1 a KDE KDE 3.1.1 KDE KDE 3.1 KDE KDE 3.0.5 b KDE KDE 3.0.5 a KDE KDE 3.0.5 KDE KDE 3.0.4 KDE KDE 3.0.3 a KDE KDE 3.0.3 KDE KDE 3.0.2 KDE KDE 3.0.1 KDE KDE 3.0 KDE KDE 2.2.2 KDE KDE 2.2.1 KDE KDE 2.2 KDE KDE 2.1.2 KDE KDE 2.1.1 KDE KDE 2.1 KDE KDE 2.0.1 KDE KDE 2.0 BETA KDE KDE 2.0 KDE KDE 1.2 KDE KDE 1.1.2 KDE KDE 1.1.1 KDE KDE 1.1 Gentoo Linux ALT Linux ALT Linux Junior 2.3 ALT Linux ALT Linux Compact 2.3 |
| Not Vulnerable: |
S.u.S.E. Linux Personal 9.3 KDE KDE 3.4 |
Discussion
KDE DCOPServer Local Denial of Service Vulnerability
KDE's Desktop Communication Protocol (DCOP) daemon is affected by a local denial-of-service vulnerability.
Reportedly, a user's DCOPServer can be locked up by causing the authentication process to stall.
All versions of KDE prior to 3.4 are affected by this issue.
This BID will be updated when more information is available.
KDE's Desktop Communication Protocol (DCOP) daemon is affected by a local denial-of-service vulnerability.
Reportedly, a user's DCOPServer can be locked up by causing the authentication process to stall.
All versions of KDE prior to 3.4 are affected by this issue.
This BID will be updated when more information is available.
Exploit / POC
KDE DCOPServer Local Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
KDE DCOPServer Local Denial of Service Vulnerability
Solution:
Please see the referenced advisories for more information.
KDE KDE 1.1
KDE KDE 1.1.1
KDE KDE 1.1.2
KDE KDE 1.2
KDE KDE 2.0 BETA
KDE KDE 2.0
KDE KDE 2.0.1
KDE KDE 2.1
KDE KDE 2.1.1
KDE KDE 2.1.2
KDE KDE 2.2
KDE KDE 2.2.1
KDE KDE 2.2.2
KDE KDE 3.0
KDE KDE 3.0.1
KDE KDE 3.0.2
KDE KDE 3.0.3 a
KDE KDE 3.0.3
KDE KDE 3.0.4
KDE KDE 3.0.5
KDE KDE 3.0.5 b
KDE KDE 3.0.5 a
KDE KDE 3.1
KDE KDE 3.1.1 a
KDE KDE 3.1.1
KDE KDE 3.1.2
KDE KDE 3.1.3
KDE KDE 3.1.4
KDE KDE 3.1.5
KDE KDE 3.2
KDE KDE 3.2.1
KDE KDE 3.2.2
KDE KDE 3.2.3
KDE KDE 3.3
KDE KDE 3.3.1
KDE KDE 3.3.2
Solution:
Please see the referenced advisories for more information.
KDE KDE 1.1
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 1.1.1
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 1.1.2
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 1.2
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 2.0 BETA
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 2.0
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 2.0.1
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 2.1
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 2.1.1
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 2.1.2
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 2.2
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 2.2.1
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 2.2.2
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.0
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.0.1
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.0.2
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.0.3 a
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.0.3
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.0.4
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.0.5
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.0.5 b
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.0.5 a
-
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.1
-
KDE post-3.1.5-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.1.1 a
-
KDE post-3.1.5-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.1.1
-
KDE post-3.1.5-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.1.2
-
KDE post-3.1.5-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.1.3
-
KDE post-3.1.5-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.1.4
-
KDE post-3.1.5-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.1.5
-
KDE post-3.1.5-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.2
-
KDE post-3.2.3-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/ -
Mandrake kdelibs-common-3.2-36.12.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kdelibs-common-3.2-36.12.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kdelibs-common-3.2-36.12.C30mdk.i586.rpm
Mandrake Corporate 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kdelibs-common-3.2-36.12.C30mdk.x86_64.rpm
Mandrake Corporate 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64kdecore4-3.2-36.12.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64kdecore4-3.2-36.12.C30mdk.x86_64.rpm
Mandrake Corporate 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64kdecore4-devel-3.2-36.12.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64kdecore4-devel-3.2-36.12.C30mdk.x86_64.rpm
Mandrake Corporate 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libkdecore4-3.2-36.12.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libkdecore4-3.2-36.12.C30mdk.i586.rpm
Mandrake Corporate 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libkdecore4-devel-3.2-36.12.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libkdecore4-devel-3.2-36.12.C30mdk.i586.rpm
Mandrake Corporate 3.0
http://www.mandrakesecure.net/en/ftp.php
KDE KDE 3.2.1
-
KDE post-3.2.3-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/ -
SuSE kdelibs3-3.2.1-44.46.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kdelibs3-3.2.1-44 .46.i586.rpm -
SuSE kdelibs3-3.2.1-44.46.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kdelibs3-3.2. 1-44.46.x86_64.rpm
KDE KDE 3.2.2
-
Fedora kdelibs-3.2.2-14.FC2.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora kdelibs-3.2.2-14.FC2.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora kdelibs-debuginfo-3.2.2-14.FC2.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora kdelibs-debuginfo-3.2.2-14.FC2.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora kdelibs-devel-3.2.2-14.FC2.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora kdelibs-devel-3.2.2-14.FC2.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
KDE post-3.2.3-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.2.3
-
KDE post-3.2.3-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/ -
Mandrake kdelibs-common-3.2.3-104.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kdelibs-common-3.2.3-104.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64kdecore4-3.2.3-104.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64kdecore4-devel-3.2.3-104.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libkdecore4-3.2.3-104.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libkdecore4-3.2.3-104.2.101mdk.i586.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libkdecore4-devel-3.2.3-104.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php
KDE KDE 3.3
-
Fedora kdelibs-3.3.1-2.9.FC3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kdelibs-3.3.1-2.9.FC3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kdelibs-debuginfo-3.3.1-2.9.FC3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kdelibs-debuginfo-3.3.1-2.9.FC3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kdelibs-devel-3.3.1-2.9.FC3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kdelibs-devel-3.3.1-2.9.FC3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
KDE post-3.3.2-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/ -
SuSE kdelibs3-3.3.0-34.5.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/kdelibs3-3.3.0-34 .5.i586.rpm -
SuSE kdelibs3-3.3.0-34.5.x86_64.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/kdelibs3-3.3.0- 34.5.x86_64.rpm
KDE KDE 3.3.1
-
KDE post-3.3.2-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/
KDE KDE 3.3.2
-
KDE post-3.3.2-kdelibs-dcop.patch
ftp://ftp.kde.org/pub/kde/security_patches -
KDE KDE 3.4
http://www.kde.org/download/
References
KDE DCOPServer Local Denial of Service Vulnerability
References:
References: