CVE-2003-0706

mah-jong 1.5.6 - Denial of Service via Tight Loop

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0706. PoCs published by jsk.

AI-analyzed exploit summary This Perl script exploits a denial of service vulnerability in the mah-jong game server by sending a malformed 'Connect' command, causing the server to enter a tight loop and become unresponsive.

Description

Unknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop).

Exploits (1)

exploitdb WORKING POC VERIFIED
by jsk · perldoslinux
https://www.exploit-db.com/exploits/23116

This Perl script exploits a denial of service vulnerability in the mah-jong game server by sending a malformed 'Connect' command, causing the server to enter a tight loop and become unresponsive.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: mahJong 1.6
No auth needed
Prerequisites: Network access to the target server · Target server running mahJong 1.6
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Patch vendor-advisory x_refsource_debian
http://www.debian.org/security/2003/dsa-378

Scores

EPSS 0.0332
EPSS Percentile 87.0%

Details

Status published
Products (1)
nicolas_boullis/mah-jong 1.4
Published Sep 17, 2003
Tracked Since Feb 18, 2026