/usr/bin/kdesud has a DISPLAY environment variable overflow which could allow for the execution of arbitrary code.