CVE-2002-0468
Summary
| CVE | CVE-2002-0468 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-08-12 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or other files. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ecartis | Ecartis | 1.0.0_snapshot_2002-01-21 | All | All | All |
| Application | Ecartis | Ecartis | 1.0.0_snapshot_2002-01-25 | All | All | All |
| Application | Listar | Listar | 0.126a | All | All | All |
| Application | Listar | Listar | 0.127a | All | All | All |
| Application | Listar | Listar | 0.129a | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| online.securityfocus.com/archive/82/258763 | af854a3a-2127-422b-91ae-364da2661108 | online.securityfocus.com | Vendor Advisory |
| Ecartis/Listar Multiple Local Buffer Overflow Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| ISS X-Force Database: ecartis-local-bo (8445): Ecartis local buffer overflows in moderate.c and lcgi.c | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| ecartis: Modular Mailing List Manager | af854a3a-2127-422b-91ae-364da2661108 | www.ecartis.org | |
| SecurityFocus HOME Mailing List: BugTraq | af854a3a-2127-422b-91ae-364da2661108 | online.securityfocus.com | Vendor Advisory |
| '[ESupp] Re: Fwd: Ecartis/Listar multiple vulnerabilities' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityFocus HOME Mailing List: BugTraq | af854a3a-2127-422b-91ae-364da2661108 | online.securityfocus.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.