Executive brief
A security vulnerability exists in kppp, a dialer application used in the KDE desktop environment to manage internet connections. A local user on the system can exploit this flaw to gain full administrative (root) control over the computer. This could allow an unauthorized person to access sensitive files, modify system settings, or disrupt operations.
Technical details
A stack-based buffer overflow exists in the kppp utility within the KDE desktop environment. The vulnerability is triggered when the application processes an excessively long string passed via the '-c' (account_name) command-line argument. Because kppp was often installed with setuid root permissions to manage network interfaces, a local attacker can exploit this overflow to overwrite the instruction pointer and execute arbitrary code with elevated privileges. This results in a complete compromise of the local system. The issue was originally identified in 1998 and affects early versions of the KDE suite.
Affected products
- KDE KDE kppp
Timeline
- 1998-04-29: disclosed: Initial public disclosure and NVD publication