CVE-2008-1671
start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service and possibly execute arbitrary code via "user-influenceable input" (probably command-line arguments) that cause start_kdeinit to send SIGUSR1 signals to other processes.
Date published : 2008-04-28
http://www.securityfocus.com/bid/28938
ftp://ftp.kde.org/pub/kde/security_patches/post-kde-3.5.5-kinit.diff