First published: Thu Nov 21 2002(Updated: )
Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote attackers to execute arbitrary code via a certain "lan://" URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE KDE | =2.2.1 | |
KDE KDE | =2.1.2 | |
KDE KDE | =3.0.2 | |
KDE KDE | =2.2 | |
KDE KDE | =2.1 | |
KDE KDE | =3.0.1 | |
KDE KDE | =3.0 | |
KDE KDE | =2.1.1 | |
KDE KDE | =2.2.2 | |
KDE KDE | =3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1306 has a high severity rating due to multiple buffer overflows that can lead to remote code execution.
To mitigate CVE-2002-1306, upgrade to KDE version 3.0.4 or later, which contains patches for this vulnerability.
CVE-2002-1306 affects KDE versions 2.1 through 3.0.3, including specific early 2.x and 3.x versions.
Yes, CVE-2002-1306 can be exploited remotely via the "lisa" daemon using a vulnerable "lan://" URL.
Users of KDE versions 2.x for 2.1 and later, and 3.x prior to 3.0.4, are at risk due to this vulnerability.