Vulnerabilities > CVE-2002-1158 - Local Buffer Overflow vulnerability in Canna Server

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
canna
nessus

Summary

Buffer overflow in the irw_through function for Canna 3.5b2 and earlier allows local users to execute arbitrary code as the bin user.

Vulnerable Configurations

Part Description Count
Application
Canna
1

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-224.NASL
    descriptionSeveral vulnerabilities have been discovered in canna, a Japanese input system. The Common Vulnerabilities and Exposures (CVE) project identified the following vulnerabilities : - CAN-2002-1158 (BugTraq Id 6351):
    last seen2020-06-01
    modified2020-06-02
    plugin id15061
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/15061
    titleDebian DSA-224-1 : canna - buffer overflow and more
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2002-261.NASL
    descriptionThe Canna server, used for Japanese character input, has two security vulnerabilities including an exploitable buffer overflow that allows a local user to gain
    last seen2020-06-01
    modified2020-06-02
    plugin id12336
    published2004-07-06
    reporterThis script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/12336
    titleRHEL 2.1 : Canna (RHSA-2002:261)

Redhat

advisories
  • rhsa
    idRHSA-2002:246
  • rhsa
    idRHSA-2002:261
  • rhsa
    idRHSA-2003:115