Melange Chat System Long Filename Buffer Overflow Vulnerability
BID:4510
Info
Melange Chat System Long Filename Buffer Overflow Vulnerability
| Bugtraq ID: | 4510 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0552 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 14 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by Leon Harris <[email protected]>. |
| Vulnerable: |
Melange Melange Chat System 2.0.2 Beta 2 |
| Not Vulnerable: | |
Discussion
Melange Chat System Long Filename Buffer Overflow Vulnerability
Melange Chat Systems is a chat application developed by Christian Walter. Currently support for this application is no longer available.
An issue has been reported in Melange Chat Systems, which could allow a user to initiate a buffer overflow.
The overflow occurs if the configuration file is renamed with an unusually long filename.
Melange Chat Systems is a chat application developed by Christian Walter. Currently support for this application is no longer available.
An issue has been reported in Melange Chat Systems, which could allow a user to initiate a buffer overflow.
The overflow occurs if the configuration file is renamed with an unusually long filename.
Solution / Fix
Melange Chat System Long Filename Buffer Overflow Vulnerability
Solution:
The discoverer of this issue Leon Harris <[email protected]>, has released a patch for this issue. Administrators who intend to apply this patch should be aware that this is an unofficial patch, and should be handled accordingly. The patch is available in the message listed in the references section of this alert.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The discoverer of this issue Leon Harris <[email protected]>, has released a patch for this issue. Administrators who intend to apply this patch should be aware that this is an unofficial patch, and should be handled accordingly. The patch is available in the message listed in the references section of this alert.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.