E-Mail:
Get our new Windows 7 eBook (PDF) for $7 with 70+ Tips. Download Now!

Multiple IRC Vulnerabilities in Trillian

Multiple vulnerabilities have been discovered in Trillian versions 3.1 and lower IRC module.

Remote exploitation of multiple vulnerabilities in the Internet Relay Chat (IRC) module of Cerulean Studios’ Trillian could allow for the interception of private conversations or execution of code as the currently logged on user.

When handling long CTCP PING messages containing UTF-8 characters, it is possible to cause the Trillian IRC client to return a malformed response to the server. This malformed response is truncated and is missing the terminating newline character. This could allow the next line sent to the server to be improperly sent to an attacker.

When a user highlights a URL in an IRC message window Trillian copies the data to an internal buffer. If the URL contains a long string of UTF-8 characters, it is possible to overflow a heap based buffer corrupting memory in a way that could allow for code execution.

A heap overflow can be triggered remotely when the Trillian IRC module receives a message that contains a font face HTML tag with the face attribute set to a long UTF-8 string.”

All Trillian users that use it to connect to any IRC server or IRC network are urged to immediately upgrade to Trillian 3.1.5.0 or better or use a (safe and full featured) IRC client.

[Cerulean Studios Trillian Multiple IRC Vulnerabilities]

[tags]Trillian, Trillian IRC Module, Internet Relay Chat, IRC, security, vulnerability[/tags]

What Do You Think?

 

Posted Recently

Up to 40% off Logitech Harmony One Touch Screen Advanced Universal Remote + Free Shipping!

Motorola Droid A855 Phone for only $150 + Free Shipping!

Up to $200 off Data Robotics DroboPro 8-Bay USB 2.0/FireWire 800/iSCSI Storage Array

Up to $30 off Apple Mac mini with 2.53 GHz Core 2 Duo + 320 GB HD + 4 GB RAM + Free Shipping!

Nintendo Wii Console with Wii Fit Plus, $50 Gift Card for $290 + Free Shipping!

Logitech Performance Mouse MX for as low as $80.10 + Free Shipping!

Char-Broil The Big Easy Oil-Less Infrared Turkey Fryer for $140 + Free Shipping!

Logitech MX 1100 Cordless Laser Mouse for as low as $40 + Free Shipping!

Western Digital 2 TB Caviar Green SATA Hard Drive for $190 + Free Shipping!

Buy an LG Blu-ray Player, Get 3 Blu-ray Movies for Free!

Logitech Harmony 890 Universal Remote Control for $100 + Free Shipping!!

Seagate FreeAgent Go 250 GB Portable External Hard Drive for $60 + Free Shipping!

Up to 50% off TomTom GO 720 Portable GPS Navigator + Free Shipping!

Logitech Harmony 880 Advanced Universal Remote Control for $124 + Free Shipping!

Up to $100 Gift Card with Select ASUS Thin and Light Laptops

TomTom GO 730 Portable GPS Navigator for as low as $120 + Free Shipping!

Western Digital 1.5 TB Caviar Green SATA Desktop Hard Drive for $109 + Free Shipping!

Save up to 39% and get free shipping on Harmony 1100 Advanced Touch Screen Universal Remote Control

Panasonic Lumix DMC-ZS3 10MP Digital Camera for $285 + Free Shipping!

Dell Inspiron Mini Netbook with Integrated TV Tuner for $310 + Free Shipping!

66 queries / 1.207 seconds.