Tutorial

Go Back   Tutorial > Technology > Home security tips

Forum overview

Latest topics
Show:

Portalsearch

Advanced Search

Statistic
Topics: 34936
We welcome our newest user: VomaHeeseex
New users:
11-22-2008
- VomaHeeseex
11-22-2008
- ToomiFearma
11-22-2008
- Greevedic
11-22-2008
- OnesStelsnemi
11-21-2008
- Hauhpaimupt


Cerulean Studios Trillian Multiple IRC Vulnerabilities


Home security tips

Sponsored Links:

Reply
 
Thread Tools Search this Thread Display Modes

  #1  
Old 05-02-2007, 12:13 AM
LapTop's Avatar
LapTop LapTop is offline
Administrator
 
Join Date: Apr 2007
Posts: 21,889
Cerulean Studios Trillian Multiple IRC Vulnerabilities

Sponsored Links:
A close friend, who knows I use Trillian for the convenience of an all-in-one chat program, alerted me to the IDefense Labs PUBLIC ADVISORY 04.30.07, copied below.

If you use Trillian but would rather not read all the technical jargon below, make sure that you update to the latest version! Trillian 3.1.5.1 is available from Download.com.

Thanks, ETR!

"Cerulean Studios Trillian Multiple IRC Vulnerabilities
I. BACKGROUND

Cerulean Studios Trillian is a multi-protocol chat application that supports IRC, ICQ, AIM and MSN protocols. More information can be found on the vendor's site at the following URL. http://www.ceruleanstudios.com/learn/
II. DESCRIPTION

Remote exploitation of multiple vulnerabilities in the Internet Relay Chat (IRC) module of Cerulean Studios' Trillian could allow for the interception of private conversations or execution of code as the currently logged on user.
When handling long CTCP PING messages containing UTF-8 characters, it is possible to cause the Trillian IRC client to return a malformed response to the server. This malformed response is truncated and is missing the terminating newline character. This could allow the next line sent to the server to be improperly sent to an attacker.
When a user highlights a URL in an IRC message window Trillian copies the data to an internal buffer. If the URL contains a long string of UTF-8 characters, it is possible to overflow a heap based buffer corrupting memory in a way that could allow for code execution.
A heap overflow can be triggered remotely when the Trillian IRC module receives a message that contains a font face HTML tag with the face attribute set to a long UTF-8 string.
III. ANALYSIS

Exploitation of this vulnerability allows remote attackers to intercept private communications for Trillian IRC users or execute code with the credentials of the currently logged on user.
In order to exploit the highlighted URL vulnerability, users would have to highlight the malicious URL.
IV. DETECTION

iDefense has confirmed the existence of this vulnerability in Cerulean Studios Trillian 3.1.
V. WORKAROUND

iDefense is currently unaware of any effective workaround for this issue.
VI. VENDOR RESPONSE

Cerulean Studios has addressed these vulnerabilities within version 3.1.5.0 of Trillian. For more information, visit their blog at the following URL.
http://blog.ceruleanstudios.com/"


Sponsored Links:
Reply With Quote
Reply

Sponsored Links:

Compare price

Compare products

Download software


Free Download Softwware


Tags: , , , , ,



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Multiple Remote Desktop LapTop Xp tips 0 04-29-2007 12:51 AM
Creating Multiple Streams of Affiliate Marketing Income LapTop Marketing tips 0 04-28-2007 04:52 AM



All times are GMT. The time now is 12:21 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.

RSS 2.0 HOME