Cerulean Studios Trillian Client MSN Module Remote Buffer Overflow Vulnerability
BID:11142
Info
Cerulean Studios Trillian Client MSN Module Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11142 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2004 12:00AM |
| Updated: | Sep 08 2004 12:00AM |
| Credit: | Discovery is credited to Komrade <[email protected]>. |
| Vulnerable: |
Cerulean Studios Trillian 0.74 i |
| Not Vulnerable: | |
Discussion
Cerulean Studios Trillian Client MSN Module Remote Buffer Overflow Vulnerability
Trillian is reported prone to a remote buffer overflow vulnerability. This issue occurs due to insufficient boundary checks performed by the application and may allow an attacker to execute arbitrary code on a vulnerable computer. This could ultimately lead to an attacker gaining unauthorized access to the computer.
The vulnerability affects the MSN module and requires an attacker to pose as an MSN server through means such as a man-in-the-middle attack.
Trillian version 0.74i is reported prone to this issue, however, it is likely that other versions are affected as well.
Trillian is reported prone to a remote buffer overflow vulnerability. This issue occurs due to insufficient boundary checks performed by the application and may allow an attacker to execute arbitrary code on a vulnerable computer. This could ultimately lead to an attacker gaining unauthorized access to the computer.
The vulnerability affects the MSN module and requires an attacker to pose as an MSN server through means such as a man-in-the-middle attack.
Trillian version 0.74i is reported prone to this issue, however, it is likely that other versions are affected as well.
Exploit / POC
Cerulean Studios Trillian Client MSN Module Remote Buffer Overflow Vulnerability
Exploit code is available:
Exploit code is available:
Solution / Fix
Cerulean Studios Trillian Client MSN Module Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Cerulean Studios Trillian Client MSN Module Remote Buffer Overflow Vulnerability
References:
References:
- Cerulean Studios Trillian 0.74i buffer overflow in MSN module (Komrade)
- Trillian Homepage (Cerulean Studios)
- Cerulean Studios Trillian 0.74i Buffer Overflow in MSN module exploit ("Jérôme" ATHIAS
)