We have received a report that one can use a simple buffer overflow exploit to gain access to the group shadow on systems running klock. There was also a problem in kvt which saved its configuration as root and not as regular user.
We recommend you upgrade your kdebase package immediately.