Impact
This vulnerability is a stack‑based buffer overflow in the OP_SERVERMESSAGE handler of aMule 2.3.3. A remote attacker can send a specially crafted message that overflows a buffer on the server side, causing the aMule process to crash and leading to a denial of service. The flaw is identified as CWE-121 and carries a CVSS score of 7.5, indicating moderate to high severity.
Affected Systems
aMule – the peer‑to‑peer file sharing application – version 2.3.3 is affected. No other vendor or product versions are listed in the CNA data.
Risk and Exploitability
The EPSS score of less than 1% suggests exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. However, because the flaw can be triggered remotely by an attacker who can send a malicious OP_SERVERMESSAGE, the risk remains for systems exposed to untrusted peers. An attacker would need to send a crafted message to the aMule server; no additional compromises are required. The impact is a crash of the aMule service, causing a service interruption in the network using it.
OpenCVE Enrichment