eMule Client Servername Format String Vulnerability
BID:8445
Info
eMule Client Servername Format String Vulnerability
| Bugtraq ID: | 8445 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2003 12:00AM |
| Updated: | Aug 17 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Stefan Esser <[email protected]>. |
| Vulnerable: |
xMule xMule 1.5.5 xMule xMule 1.5.4 xMule xMule 1.4.2 lmule lmule 1.3.1 lmule lmule 1.2.1 EMule+ EMule+ 1.0 Emule Emule 0.29 c Emule Emule 0.29 b Emule Emule 0.29 a Emule Emule 0.27 c Emule Emule 0.27 b Emule Emule 0.27 |
| Not Vulnerable: | |
Discussion
eMule Client Servername Format String Vulnerability
eMule client has been reported prone to a format string vulnerability. The issue presents itself when the client processes a malicious server name. Ultimately, a remote attacker may exploit this condition to trigger a denial of service condition in the affected client. Although unconfirmed it has been conjectured that this issue may also be exploited to reveal memory. Remote code execution is not believed to be possible.
eMule client has been reported prone to a format string vulnerability. The issue presents itself when the client processes a malicious server name. Ultimately, a remote attacker may exploit this condition to trigger a denial of service condition in the affected client. Although unconfirmed it has been conjectured that this issue may also be exploited to reveal memory. Remote code execution is not believed to be possible.