Melange Chat System /yell Remote Buffer Overflow Vulnerability
BID:4508
Info
Melange Chat System /yell Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 4508 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0552 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 14 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by Leon Harris <[email protected]>. |
| Vulnerable: |
Melange Melange Chat System 2.0.2 Beta 2 |
| Not Vulnerable: | |
Discussion
Melange Chat System /yell Remote Buffer Overflow Vulnerability
Melange Chat System is a chat server program developed by Christian Walter. Currently support for this application is no longer available.
Due to inadequate bounds checking in Melange, it is possible for users to initiate a buffer overflow.
Submitting an unusually large /yell argument composed of arbitrary data, could cause the overflow to occur.
Melange Chat System is a chat server program developed by Christian Walter. Currently support for this application is no longer available.
Due to inadequate bounds checking in Melange, it is possible for users to initiate a buffer overflow.
Submitting an unusually large /yell argument composed of arbitrary data, could cause the overflow to occur.
Exploit / POC
Melange Chat System /yell Remote Buffer Overflow Vulnerability
dvdman <[email protected]> has provided the following proof of concept:
dvdman <[email protected]> has provided the following proof of concept:
Solution / Fix
Melange Chat System /yell Remote Buffer Overflow Vulnerability
Solution:
The discoverer of this issue Leon Harris <[email protected]>, has released a patch for this issue. Administrators who intend to apply this patch should be aware that this is an unofficial patch, and should be handled accordingly. The patch is available in the message listed in the references section of this alert.
The SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The discoverer of this issue Leon Harris <[email protected]>, has released a patch for this issue. Administrators who intend to apply this patch should be aware that this is an unofficial patch, and should be handled accordingly. The patch is available in the message listed in the references section of this alert.
The SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Melange Chat System /yell Remote Buffer Overflow Vulnerability
References:
References:
- Melange Homepage (Christian Walter)