|
|
|
Vulnerability Note VU#187033Cerulean Studios Trillian Instant Messenger fails to properly handle "UTF-8" sequencesOverviewA vulnerability in Cerulean Studios Trillian Instant Messenger client may lead to execution of arbitrary code.I. DescriptionCerulean Studios Trillian Instant Messenger client fails to properly handle specially crafted UTF-8 text. A heap overflow may occur when Trillian receives a messages with malformed UTF-8 strings.II. ImpactA remote, authenticated attacker may be able to execute arbitrary code with the privileges of the user or cause a denial-of-service condition by sending the client a message.III. SolutionUpdateCerulean Studios has released an update to address this issue. See the Cerulean Studios Blog for more information.
References
This vulnerability was reported in iDefense Public Advisory 6.18.07. iDefense credits www.BlurredLogic.com with reporting this issue. This document was written by Chris Taschner.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||