Vulnerabilities > CVE-2002-1159 - Denial Of Service vulnerability in Canna 3.5B2/3.6

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
canna
nessus

Summary

Canna 3.6 and earlier does not properly validate requests, which allows remote attackers to cause a denial of service or information leak.

Vulnerable Configurations

Part Description Count
Application
Canna
2

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-224.NASL
    descriptionSeveral vulnerabilities have been discovered in canna, a Japanese input system. The Common Vulnerabilities and Exposures (CVE) project identified the following vulnerabilities : - CAN-2002-1158 (BugTraq Id 6351):
    last seen2020-06-01
    modified2020-06-02
    plugin id15061
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/15061
    titleDebian DSA-224-1 : canna - buffer overflow and more
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2002-261.NASL
    descriptionThe Canna server, used for Japanese character input, has two security vulnerabilities including an exploitable buffer overflow that allows a local user to gain
    last seen2020-06-01
    modified2020-06-02
    plugin id12336
    published2004-07-06
    reporterThis script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/12336
    titleRHEL 2.1 : Canna (RHSA-2002:261)

Redhat

advisories
  • rhsa
    idRHSA-2002:246
  • rhsa
    idRHSA-2002:261
  • rhsa
    idRHSA-2003:115