Trillian IRC Module Format String Vulnerability
BID:5388
Info
Trillian IRC Module Format String Vulnerability
| Bugtraq ID: | 5388 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2002 12:00AM |
| Updated: | Aug 02 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to Josh ([email protected]) and omega ([email protected]). |
| Vulnerable: |
Cerulean Studios Trillian 0.725 Cerulean Studios Trillian 0.73 |
| Not Vulnerable: | |
Discussion
Trillian IRC Module Format String Vulnerability
A format string vulnerability has been reported in the Trillian IRC module. An attacker can exploit this vulnerability by enticing a user to join a channel with a malicious channel name (e.g. #%n%n%n). An attacker in control of a malicious server may exploit vulnerable clients who have connected.
A format string vulnerability has been reported in the Trillian IRC module. An attacker can exploit this vulnerability by enticing a user to join a channel with a malicious channel name (e.g. #%n%n%n). An attacker in control of a malicious server may exploit vulnerable clients who have connected.
Exploit / POC
Trillian IRC Module Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.