PT-2007-3803 · Cerulean Studios · Trillian Pro
Published
2007-05-02
·
Updated
2017-07-29
·
CVE-2007-2479
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cerulean Studios Trillian Pro versions prior to 3.1.5.1
Description
The issue allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters. This generates a malformed response that is not truncated by a newline, which can cause portions of a server message to be sent to the attacker.
Recommendations
For versions prior to 3.1.5.1, update to version 3.1.5.1 or later to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trillian Pro