CVE-2002-1247: Buffer Overflow
Published Nov 14, 2002
·Updated
Buffer overflow in LISa allows local users to gain access to a raw socket via a long LOGNAME environment variable for the resLISa daemon.
Affected Software
12 affected components
KDE Klisa=2.2.2
LISa LISa=0.1
LISa LISa=0.1.2
KDE kde=2.0
KDE kde=3.0.2
KDE kde=2.2
KDE kde=2.1
KDE kde=3.0.1
KDE kde=3.0.4
KDE kde=3.0
KDE kde=3.0.3
KDE kde=3.0.3a
Remediation
Patch Available
Patch Available
Event History
Nov 14, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1247?
CVE-2002-1247 has a moderate severity level due to the potential for local users to gain unauthorized access to a raw socket.
2
How do I fix CVE-2002-1247?
To fix CVE-2002-1247, you should update to the latest version of the affected software that addresses the buffer overflow vulnerability.
3
Which software versions are affected by CVE-2002-1247?
CVE-2002-1247 affects LISa version 0.1, 0.1.2, and various KDE versions up to 3.0.4.
4
Can CVE-2002-1247 be exploited remotely?
CVE-2002-1247 cannot be exploited remotely as it is a local vulnerability that requires access to the affected system.
5
What are the potential impacts of exploiting CVE-2002-1247?
Exploiting CVE-2002-1247 can lead to local privilege escalation, allowing attackers to gain elevated access to system resources.