|
Trillian buffer overflows
|
|
Secunia Advisory:
|
SA7133
|
|
|
Release Date:
|
2002-09-19
|
|
Last Update:
|
2002-09-24
|
|
Popularity:
|
3,217 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Unpatched
|
|
| Software: | Trillian 0.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: It is possible to cause a buffer overflow in Trillian when it processes a PRIVMSG command that is larger than 206 bytes.
This can be used to DoS and possibly also inject arbitrary code to the victims system, which would give an attacker control of the system.
Also in the raw 221 (usermode) and the JOIN command does buffer overflows exist.
More DoS attacks possible, large raw messages, any data amounts over 4095 bytes, PART command with references to a channel which you are not connected to.
The above issues are all related to IRC, however when connected to AIM services Trillian is vulnerable to a simple DoS attack, send an AOL instant message with this string anywhere in the message "P > O < C" this will cause Trillian to crash.
In our opinion it seems that the guys who made Trillian has been a bit too fast coding a great utility, without considering the possible consequences of not verifying all input that is supplied by users or servers to the program.
Solution: With the vulnerabilities we have seen in Trillian lately, we highly recommend that companies who allow the use of IRC, employ other clients than Trillian.
Provided and/or discovered by: Lance Fitz-Herbert
Spikeman
Changelog: 20/09/2002 Yet another buffer overflow is posted, this time in the JOIN command, Lance Fitz-Herbert
22/09/2002 Yet another buffer overflow is posted, this time in raw 221, Lance Fitz-Herbert
23/09/2002 More issues, this time only DoS (raw, part and general data buffer), Lance Fitz-Herbert
24/09/2002 AIM DoS, Spikeman
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
6th Oct, 2008
|
New advisories:
|
19 |
|
New vulnerabilities:
|
52 |
|
Updated advisories:
|
26 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Solutions | More...
|
|