PT-2005-1678 · Cerulean Studios · Trillian
Tal Zeltzer
·
Publicado
2005-03-02
·
Atualizado
2016-10-18
·
CVE-2005-0633
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Trillian versions 3.0
Description
The issue is caused by a buffer overflow that occurs when a crafted PNG image file is processed, allowing remote attackers to execute arbitrary code. Additionally, a remote denial of service can be triggered when a malicious PNG image is sent via the MSN protocol, resulting in loss of availability for the service.
Recommendations
For Trillian version 3.0, update to a newer version that contains a fix for this issue to prevent remote code execution and denial of service attacks.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Trillian