Vulnerability Description
Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote attackers to execute arbitrary code via a certain "lan://" URL.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kde | Kde | 2.1 |
References
- http://marc.info/?l=bugtraq&m=103712329102632&w=2
- http://marc.info/?l=bugtraq&m=103728981029342&w=2
- http://www.ciac.org/ciac/bulletins/n-020.shtml
- http://www.debian.org/security/2002/dsa-214
- http://www.iss.net/security_center/static/10597.php
- http://www.iss.net/security_center/static/10598.phpVendor Advisory
- http://www.kde.org/info/security/advisory-20021111-2.txtPatchVendor Advisory
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-080.php
- http://www.novell.com/linux/security/advisories/2002_042_kdenetwork.html
- http://www.redhat.com/support/errata/RHSA-2002-220.html
- http://marc.info/?l=bugtraq&m=103712329102632&w=2
- http://marc.info/?l=bugtraq&m=103728981029342&w=2
- http://www.ciac.org/ciac/bulletins/n-020.shtml
- http://www.debian.org/security/2002/dsa-214
- http://www.iss.net/security_center/static/10597.php
FAQ
What is CVE-2002-1306?
CVE-2002-1306 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote ...
How severe is CVE-2002-1306?
CVE-2002-1306 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1306?
Check the references section above for vendor advisories and patch information. Affected products include: Kde Kde.