Multiple flaws detected in Cerulean Studios IM software

By

Multiple vulnerabilities have been discovered in Cerulean Studios instant messaging software, Trillian, which could be exploited by a malicious attacker to steal personal data and compromise an affected computer.

Multiple flaws detected in Cerulean Studios IM software
Trillian is a popular chat application that supports the IRC, ICQ, AIM and MSN protocols. Remote exploitation of the flaw in the IRC module of the software could allow an attacker to intercept private conversations and execute arbitrary code as the currently logged on user.

Another of the vulnerabilities is caused by an error in the way the tool handles long CTCP PING messages, which can be used to cause a vulnerable user to inadvertently send sensitive information to the hacker. A heap overflow error causes another flaw when highlighting long URLs, which can be exploited by remote attackers to execute arbitrary code.

The flaws affect Cerulean Studios Trillian version 3.1. The US-based software company has addressed the bugs within version 3.1.5.0.
Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Palo Alto Networks in talks to buy CyberArk

Palo Alto Networks in talks to buy CyberArk

Gov to encourage vuln research, puts insurers and NFPs on notice

Gov to encourage vuln research, puts insurers and NFPs on notice

"Scattered Spider" evolves with new ransomware and social engineering tactics

"Scattered Spider" evolves with new ransomware and social engineering tactics

Allianz Life says majority of US customers' data stolen in hack

Allianz Life says majority of US customers' data stolen in hack

Log In

  |  Forgot your password?