Secunia Logo
Netsikker nu! 2008
 
Trillian buffer overflows
Secunia Advisory: SA7133
Release Date: 2002-09-19
Last Update: 2002-09-24
Popularity: 3,217 views

Critical:
Moderately critical
Impact: System access
Where: From remote
Solution Status: Unpatched

Software:Trillian 0.x

Subscribe: Instant alerts on relevant vulnerabilities


Description:
It is possible to cause a buffer overflow in Trillian when it processes a PRIVMSG command that is larger than 206 bytes.

This can be used to DoS and possibly also inject arbitrary code to the victims system, which would give an attacker control of the system.

Also in the raw 221 (usermode) and the JOIN command does buffer overflows exist.

More DoS attacks possible, large raw messages, any data amounts over 4095 bytes, PART command with references to a channel which you are not connected to.

The above issues are all related to IRC, however when connected to AIM services Trillian is vulnerable to a simple DoS attack, send an AOL instant message with this string anywhere in the message "P > O < C" this will cause Trillian to crash.

In our opinion it seems that the guys who made Trillian has been a bit too fast coding a great utility, without considering the possible consequences of not verifying all input that is supplied by users or servers to the program.

Solution:
With the vulnerabilities we have seen in Trillian lately, we highly recommend that companies who allow the use of IRC, employ other clients than Trillian.

Provided and/or discovered by:
Lance Fitz-Herbert
Spikeman

Changelog:
20/09/2002 Yet another buffer overflow is posted, this time in the JOIN command, Lance Fitz-Herbert
22/09/2002 Yet another buffer overflow is posted, this time in raw 221, Lance Fitz-Herbert
23/09/2002 More issues, this time only DoS (raw, part and general data buffer), Lance Fitz-Herbert
24/09/2002 AIM DoS, Spikeman


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. phpBB "gen_rand_string()" Predictable RNG Weakness // 112 views
2. phpBB Avatar Script Insertion Vulnerability // 63 views
3. phpBB "url" bbcode Script Insertion Vulnerability // 62 views
4. phpBB BBcode "url" Script Insertion Vulnerability // 61 views
5. phpBB Avatar Functions Information Disclosure and Deletion // 45 views
6. VMware ESX Server Sun Java JDK / JRE Multiple Vulnerabilities // 42 views
7. Microsoft Windows Vista Page Fault Handling Denial of Service // 42 views
8. VMware VirtualCenter Multiple Vulnerabilities // 31 views
9. Serv-U File Renaming Directory Traversal and STOU Denial of Service // 30 views
10. VMware ESX / ESXi "JMP" Privilege Escalation Vulnerability // 25 views