Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long argument in the /yell command, (2) long lines in the /etc/melange.conf configuration file, (3) long file names, or possibly other attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Melange聊天系统melange.conf配置行处理存在缓冲区溢出漏洞
Vulnerability Description
Melange是一款Christian Walter开发的聊天服务程序,当前程序作者已经没有对这个应用程序进行维护。 Melange在对melange.conf配置文件中的配置行内容缺少正确的边界检查,可导致缓冲溢出。 本地攻击者可以编译melange.conf配置文件,在配置文件中插入超长的一行内容就可以导致melange产生缓冲溢出,导致拒绝服务攻击,或以melange进程的权限执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A