20020414 Vulnerabilities in the Melange Chat Servermailing list
http://archives.neohapsis.com/archives/bugtraq/2002-04/0157.html CVE-2002-0552
Melange Chat System 2.0.2 Beta 2 - '/yell' Remote Buffer Overflow
Record summary
CVE-2002-0552 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long argument in the /yell command, (2) long lines in the /etc/melange.conf configuration file, (3) long file names, or possibly other attacks.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMelange Chat System 2.0.2 Beta 2 - '/yell' Remote Buffer OverflowExploitDB exploitby DVDMANNot analyzed1 file
References
920020416 Melange Chat POC DOSmailing list
http://online.securityfocus.com/archive/1/267932 melange-chat-yell-bo(8842)vdb entry
http://www.iss.net/security_center/static/8842.php melange-chat-config-bo(8845)vdb entry
http://www.iss.net/security_center/static/8845.php melange-chat-filename-bo(8846)vdb entry
http://www.iss.net/security_center/static/8846.php 4508vdb entry
http://www.securityfocus.com/bid/4508 4509vdb entry
http://www.securityfocus.com/bid/4509 4510vdb entry
http://www.securityfocus.com/bid/4510 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0552