CVE-2002-0468 describes multiple buffer overflow vulnerabilities in Ecartis (formerly Listar) 1.0.0, specifically in snapshot 20020427 and earlier versions. These flaws, primarily a long command-line argument in core.c and potential sprintf() misuse in several other files, allow local users to gain elevated privileges. The vulnerability has a CVSS score of 4.6, indicating a low attack complexity and requiring local access, but with potential for partial confidentiality, integrity, and availability impact. While not listed on the KEV catalog or having Metasploit/Nuclei modules, exploit code is publicly available on ExploitDB, and it has garnered significant community discussion, though no active exploitation or media coverage is reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0_snapshot_2002-01-21CPE matchmatch criteria | cpe:2.3:a:ecartis:ecartis:1.0.0_snapshot_2002-01-21:*:*:*:*:*:*:* | ||
1.0.0_snapshot_2002-01-25CPE matchmatch criteria | cpe:2.3:a:ecartis:ecartis:1.0.0_snapshot_2002-01-25:*:*:*:*:*:*:* | ||
0.126aCPE matchmatch criteria | cpe:2.3:a:listar:listar:0.126a:*:*:*:*:*:*:* | ||
0.127aCPE matchmatch criteria | cpe:2.3:a:listar:listar:0.127a:*:*:*:*:*:*:* | ||
0.129aCPE matchmatch criteria | cpe:2.3:a:listar:listar:0.129a:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.