The client_cmd function in Empire 4.3.2 and earlier allows remote attackers to cause a denial of service (application crash) by causing long text strings to be appended to the player->client buffer, which causes an invalid memory access.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Empire_server | Empire_server | 4.3.0 (including) | 4.3.0 (including) |
| Empire_server | Empire_server | 4.3.2 (including) | 4.3.2 (including) |