Trillian MSN Module Messenger Server Overflow

rik

OSNN Addict
Joined
22 Mar 2004
Messages
115
Article found in it's original context here

OSVDB ID: 9777
Rating: TBD
Disclosure Date: Sep 8, 2004


Description:
Trillian contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when a boundary error within the MSN module occurs. It is possible that the flaw may allow a malicious to gain access to the target system resulting in a loss of integrity.



Technical Description:
This vulnerability can be exploited to create a buffer overflow by sending a long string, approximately 4096 bytes in length, followed by a new line character from an MSN messenger server.

To exploit this flaw an attacker must either change intercepted traffic sent from an MSN messenger server to the target or get the target to connect to a malicious MSN messenger server.



Vulnerability Classification:
Remote/Network Access Required
Infrastructure Attack
Loss Of Integrity
Exploit Available


Products:
Cerulean Studios Trillian 0.74i






Solution:
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.



External References:

Generic Exploit URL: http://unsecure.altervista.org/security/trillianbof.c
ISS X-Force ID: 17292
Secunia Advisory ID: 12487
Vendor URL: http://www.trillian.cc/
Vendor URL: http://www.ceruleanstudios.com/
Other Advisory URL: http://unsecure.altervista.org/security/trillian.htm
Security Mail List Post: http://archives.neohapsis.com/archives/bugtraq/2004-09/0069.html
Security Tracker: 1011186


Credit:

Komrade


Vulnerability Status:
This entry was last updated on Sep 9, 2004. If you have additional information or corrections for this vulnerability please submit them to OSVDB Moderators.
 

Members online

No members online now.

Latest profile posts

Also Hi EP and people. I found this place again while looking through a oooollllllldddd backup. I have filled over 10TB and was looking at my collection of antiques. Any bids on the 500Mhz Win 95 fix?
Any of the SP crew still out there?
Xie wrote on Electronic Punk's profile.
Impressed you have kept this alive this long EP! So many sites have come and gone. :(

Just did some crude math and I apparently joined almost 18yrs ago, how is that possible???
hello peeps... is been some time since i last came here.
Electronic Punk wrote on Sazar's profile.
Rest in peace my friend, been trying to find you and finally did in the worst way imaginable.

Forum statistics

Threads
62,015
Messages
673,494
Members
5,623
Latest member
AndersonLo
Back