Trillian IRC User Mode Numeric Remote Buffer Overflow Vulnerability
BID:5769
Info
Trillian IRC User Mode Numeric Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 5769 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1486 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Vulnerability discovery credited to Lance Fitz-Herbert <[email protected]>. |
| Vulnerable: |
Cerulean Studios Trillian 0.725 Cerulean Studios Trillian 0.74 Cerulean Studios Trillian 0.73 |
| Not Vulnerable: | |
Discussion
Trillian IRC User Mode Numeric Remote Buffer Overflow Vulnerability
Trillian is an instant messaging client that supports a number of protocols (including IRC, ICQ, MSN). It is available for Microsoft Windows systems.
It has been reported that Trillian does not perform adequate bounds checking when receiving IRC raw user mode messages. When a Trillian client receives an instruction from a server for a raw user mode change containing 251 or more bytes of data, a buffer overflow occurs. This could result in denial of service, or the execution of arbitrary attacker supplied instructions.
Trillian is an instant messaging client that supports a number of protocols (including IRC, ICQ, MSN). It is available for Microsoft Windows systems.
It has been reported that Trillian does not perform adequate bounds checking when receiving IRC raw user mode messages. When a Trillian client receives an instruction from a server for a raw user mode change containing 251 or more bytes of data, a buffer overflow occurs. This could result in denial of service, or the execution of arbitrary attacker supplied instructions.
Exploit / POC
Trillian IRC User Mode Numeric Remote Buffer Overflow Vulnerability
Exploit contributed by Lance Fitz-Herbert <[email protected]>:
Exploit contributed by Lance Fitz-Herbert <[email protected]>:
References
Trillian IRC User Mode Numeric Remote Buffer Overflow Vulnerability
References:
References:
- Trillian Homepage (Cerulean Studios)