5
CVSSv2

CVE-2002-1351

Published: 24/12/2002 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in Melange Chat System 1.10 allows remote malicious users to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) request.

Vulnerable Product Search on Vulmon Subscribe to Product

melange melange chat system 1.10

Exploits

/* Proof of Concept for Melange Chat Server 110 a lame remote bof exploit by innerphobia <up2u_@hotmailcom> 12/24/02 Credits go to: - iDefense Labs for the advisory - blink for discovering the bug - Irian for the shellcode With careful calculation it is *possible* to control even the EIP, not just one byte of EIP ...