Vulnerability CVE-2002-1247


Published: 2002-11-29   Modified: 2012-02-12

Description:
Buffer overflow in LISa allows local users to gain access to a raw socket via a long LOGNAME environment variable for the resLISa daemon.

Vendor: KDE
Product: KDE 
Version:
3.0.4
3.0.3a
3.0.3
3.0.2
3.0.1
3.0
2.2
2.1
2.0
Product: Klisa 
Version: 2.2.2;
Vendor: LISA
Product: LISA 
Version: 0.1.2; 0.1;

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0068.html
http://marc.info/?l=bugtraq&m=103704823501757&w=2
http://marc.info/?l=bugtraq&m=103712329102632&w=2
http://marc.info/?l=bugtraq&m=103728981029342&w=2
http://www.ciac.org/ciac/bulletins/n-020.shtml
http://www.debian.org/security/2002/dsa-193
http://www.idefense.com/advisory/11.11.02.txt
http://www.iss.net/security_center/static/10592.php
http://www.mandriva.com/security/advisories?name=MDKSA-2002:080
http://www.redhat.com/support/errata/RHSA-2002-220.html
http://www.securityfocus.com/bid/6157

Copyright 2019, cxsecurity.com

 

Back to Top