Multiple format string vulnerabilities in Empire Server before 4.3.1 allow attackers to cause a denial of service (crash) via the (1) load, (2) spy and (3) bomb functions.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Empire_server | Empire_server | * | 4.3.0 (including) |
Empire_server | Empire_server | 4.2.10 (including) | 4.2.10 (including) |
Empire_server | Empire_server | 4.2.11 (including) | 4.2.11 (including) |
Empire_server | Empire_server | 4.2.12 (including) | 4.2.12 (including) |
Empire_server | Empire_server | 4.2.13 (including) | 4.2.13 (including) |
Empire_server | Empire_server | 4.2.14 (including) | 4.2.14 (including) |
Empire_server | Empire_server | 4.2.15 (including) | 4.2.15 (including) |
Empire_server | Empire_server | 4.2.16 (including) | 4.2.16 (including) |
Empire_server | Empire_server | 4.2.17 (including) | 4.2.17 (including) |
Empire_server | Empire_server | 4.2.18 (including) | 4.2.18 (including) |
Empire_server | Empire_server | 4.2.19 (including) | 4.2.19 (including) |
Empire_server | Empire_server | 4.2.20 (including) | 4.2.20 (including) |
Empire_server | Empire_server | 4.2.21 (including) | 4.2.21 (including) |
Empire_server | Empire_server | 4.2.22 (including) | 4.2.22 (including) |
Empire_server | Empire_server | 4.2.23 (including) | 4.2.23 (including) |