Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Cerulean Studios Trillian Multiple IRC Module UTF-8 Vulnerabilities

Trillian is prone to multiple buffer-overflow issues and an information leak in its IRC module. These issues occur because the application fails to properly bounds-check user-supplied data before copying it into fixed-sized memory buffers and fails to respond properly to exceptional conditions.

Remote attackers may exploit these vulnerabilities to execute arbitrary machine code in the context of vulnerable Trillian clients or to steal the contents of client-server communications.

Trillian 3.1 is affected.

Further reports suggest these issues also affect the MSN and ICQ modules; other modules may also be affected. This BID will be updated pending further investigation.







 

Privacy Statement
Copyright 2008, SecurityFocus