Bug 33242 (CVE-2002-1306)

Summary: VUL-0: CVE-2002-1306: Security problems in lanbrowser
Product: [Novell Products] SUSE Security Incidents Reporter: Olaf Kirch <okir>
Component: IncidentsAssignee: E-mail List <kde-maintainers>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: security-team
Version: unspecified   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: CVE-2002-1306: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Found By: Other Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Attachments: List of issues with lanbrowser
Proposed patch - was unable to test it because lanbrowsing didn't work at all :)
new version of the patch

Description Olaf Kirch 2002-08-23 19:53:27 UTC
There are several major security problems in lanbrowser (see attached list)
Please correct these bugs.

I would also suggest to exclude the lanbrowser daemon from UL/SLES completely
by putting it into a separate package. Please discuss with autobuild people.
Comment 1 Olaf Kirch 2002-08-23 19:53:50 UTC
Created attachment 10231 [details]
List of issues with lanbrowser
Comment 2 Olaf Kirch 2002-08-30 16:47:44 UTC
Created attachment 10303 [details]
Proposed patch - was unable to test it because lanbrowsing didn't work at all :)
Comment 3 Adrian Schröter 2002-08-30 17:25:15 UTC
hm. before your patch it worked ;) 
 
I try to find it. 
Comment 4 Olaf Kirch 2002-08-30 17:33:10 UTC
On Fri, Aug 30, 2002 at 11:25:16AM +0200, bugzilla-daemon@suse.de wrote:

Sorry, I wasn't precise enough here. It didn't work yesterday when I
created the patch. Then I submitted the bug report, you fixed everything,
but I didn't get around to testing it with the latest kdenetwork3 rpm.

Olaf
Comment 5 Olaf Kirch 2002-08-30 22:44:25 UTC
Created attachment 10309 [details]
new version of the patch
Comment 6 Adrian Schröter 2002-08-31 20:07:34 UTC
patch is applied 
Comment 7 Marcus Meissner 2007-03-24 15:46:11 UTC
CVE-2002-1306
Comment 8 Thomas Biege 2009-10-13 19:32:30 UTC
CVE-2002-1306: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)