The client_cmd function in Empire 4.3.2 and earlier allows remote attackers to cause a denial of service (application crash) by causing long text strings to be appended to the player->client buffer, which causes an invalid memory access.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Empire_server | Empire_server | 4.3.0 (including) | 4.3.0 (including) |
Empire_server | Empire_server | 4.3.2 (including) | 4.3.2 (including) |