CVE-2002-1306: Buffer Overflow
Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote attackers to execute arbitrary code via a certain "lan://" URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1306?
CVE-2002-1306 has a high severity rating due to multiple buffer overflows that can lead to remote code execution.
How do I fix CVE-2002-1306?
To mitigate CVE-2002-1306, upgrade to KDE version 3.0.4 or later, which contains patches for this vulnerability.
Which versions of KDE are affected by CVE-2002-1306?
CVE-2002-1306 affects KDE versions 2.1 through 3.0.3, including specific early 2.x and 3.x versions.
Can CVE-2002-1306 be exploited remotely?
Yes, CVE-2002-1306 can be exploited remotely via the "lisa" daemon using a vulnerable "lan://" URL.
Who is affected by CVE-2002-1306?
Users of KDE versions 2.x for 2.1 and later, and 3.x prior to 3.0.4, are at risk due to this vulnerability.