CVE-2004-2466

chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.
References
Link Resource
http://archives.neohapsis.com/archives/bugtraq/2004-07/0013.html Exploit Vendor Advisory
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0077.html Exploit Vendor Advisory
http://packetstormsecurity.com/files/167892/Easy-Chat-Server-3.1-Buffer-Overflow.html
http://secunia.com/advisories/12006 Exploit Vendor Advisory
http://secunia.com/advisories/26461 Vendor Advisory
http://secunia.com/advisories/58427
http://www.autistici.org/fdonato/advisory/EasyChatServer1.2-adv.txt Exploit Vendor Advisory
http://www.exploit-db.com/exploits/33326
http://www.osvdb.org/7416 Exploit
http://www.securityfocus.com/bid/25328
http://www.securityfocus.com/bid/67384
http://www.vupen.com/english/advisories/2007/2901
https://exchange.xforce.ibmcloud.com/vulnerabilities/16629
https://exchange.xforce.ibmcloud.com/vulnerabilities/36013
https://www.exploit-db.com/exploits/4289
http://archives.neohapsis.com/archives/bugtraq/2004-07/0013.html Exploit Vendor Advisory
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0077.html Exploit Vendor Advisory
http://packetstormsecurity.com/files/167892/Easy-Chat-Server-3.1-Buffer-Overflow.html
http://secunia.com/advisories/12006 Exploit Vendor Advisory
http://secunia.com/advisories/26461 Vendor Advisory
http://secunia.com/advisories/58427
http://www.autistici.org/fdonato/advisory/EasyChatServer1.2-adv.txt Exploit Vendor Advisory
http://www.exploit-db.com/exploits/33326
http://www.osvdb.org/7416 Exploit
http://www.securityfocus.com/bid/25328
http://www.securityfocus.com/bid/67384
http://www.vupen.com/english/advisories/2007/2901
https://exchange.xforce.ibmcloud.com/vulnerabilities/16629
https://exchange.xforce.ibmcloud.com/vulnerabilities/36013
https://www.exploit-db.com/exploits/4289
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:efs_software:easy_chat_server:1.2:*:*:*:*:*:*:*
cpe:2.3:a:efs_software:easy_chat_server:2.2:*:*:*:*:*:*:*

History

20 Nov 2024, 23:53

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2004-07/0013.html - Exploit, Vendor Advisory () http://archives.neohapsis.com/archives/bugtraq/2004-07/0013.html - Exploit, Vendor Advisory
References () http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0077.html - Exploit, Vendor Advisory () http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0077.html - Exploit, Vendor Advisory
References () http://packetstormsecurity.com/files/167892/Easy-Chat-Server-3.1-Buffer-Overflow.html - () http://packetstormsecurity.com/files/167892/Easy-Chat-Server-3.1-Buffer-Overflow.html -
References () http://secunia.com/advisories/12006 - Exploit, Vendor Advisory () http://secunia.com/advisories/12006 - Exploit, Vendor Advisory
References () http://secunia.com/advisories/26461 - Vendor Advisory () http://secunia.com/advisories/26461 - Vendor Advisory
References () http://secunia.com/advisories/58427 - () http://secunia.com/advisories/58427 -
References () http://www.autistici.org/fdonato/advisory/EasyChatServer1.2-adv.txt - Exploit, Vendor Advisory () http://www.autistici.org/fdonato/advisory/EasyChatServer1.2-adv.txt - Exploit, Vendor Advisory
References () http://www.exploit-db.com/exploits/33326 - () http://www.exploit-db.com/exploits/33326 -
References () http://www.osvdb.org/7416 - Exploit () http://www.osvdb.org/7416 - Exploit
References () http://www.securityfocus.com/bid/25328 - () http://www.securityfocus.com/bid/25328 -
References () http://www.securityfocus.com/bid/67384 - () http://www.securityfocus.com/bid/67384 -
References () http://www.vupen.com/english/advisories/2007/2901 - () http://www.vupen.com/english/advisories/2007/2901 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16629 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16629 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/36013 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/36013 -
References () https://www.exploit-db.com/exploits/4289 - () https://www.exploit-db.com/exploits/4289 -

Information

Published : 2004-12-31 05:00

Updated : 2024-11-20 23:53


NVD link : CVE-2004-2466

Mitre link : CVE-2004-2466

CVE.ORG link : CVE-2004-2466


JSON object : View

Products Affected

efs_software

  • easy_chat_server
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer