7.5
CVSSv2

CVE-2002-1306

Published: 29/11/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x prior to 3.0.4, allow (1) local and possibly remote malicious users to execute arbitrary code via the "lisa" daemon, and (2) remote malicious users to execute arbitrary code via a certain "lan://" URL.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde 2.2

kde kde 2.2.1

kde kde 2.2.2

kde kde 3.0

kde kde 2.1.1

kde kde 2.1.2

kde kde 3.0.3

kde kde 2.1

kde kde 3.0.1

kde kde 3.0.2

Vendor Advisories

Olaf Kirch from SuSE Linux AG discovered another vulnerability in the klisa package, that provides a LAN information service similar to "Network Neighbourhood" The lisa daemon contains a buffer overflow vulnerability which potentially enables any local user, as well as any remote attacker on the LAN who is able to gain control of the LISa port (77 ...