7.5
CVSSv2

CVE-2002-0552

Published: 03/07/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple buffer overflows in Melange Chat server 2.02 allow remote or local malicious users to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long argument in the /yell command, (2) long lines in the /etc/melange.conf configuration file, (3) long file names, or possibly other attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

melange melange chat system 2.0.2_beta_2

Exploits

source: wwwsecurityfocuscom/bid/4508/info Melange Chat System is a chat server program developed by Christian Walter Currently support for this application is no longer available Due to inadequate bounds checking in Melange, it is possible for users to initiate a buffer overflow Submitting an unusually large /yell argument composed o ...