Multiple flaws detected in Cerulean Studios IM software

By
Follow google news

Multiple vulnerabilities have been discovered in Cerulean Studios instant messaging software, Trillian, which could be exploited by a malicious attacker to steal personal data and compromise an affected computer.

Multiple flaws detected in Cerulean Studios IM software
Trillian is a popular chat application that supports the IRC, ICQ, AIM and MSN protocols. Remote exploitation of the flaw in the IRC module of the software could allow an attacker to intercept private conversations and execute arbitrary code as the currently logged on user.

Another of the vulnerabilities is caused by an error in the way the tool handles long CTCP PING messages, which can be used to cause a vulnerable user to inadvertently send sensitive information to the hacker. A heap overflow error causes another flaw when highlighting long URLs, which can be exploited by remote attackers to execute arbitrary code.

The flaws affect Cerulean Studios Trillian version 3.1. The US-based software company has addressed the bugs within version 3.1.5.0.
Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

ServiceNow nears deal to buy cyber security startup

ServiceNow nears deal to buy cyber security startup

NSW Health clinicians "normalise" bypass of cyber security controls

NSW Health clinicians "normalise" bypass of cyber security controls

Services Australia may get powers to rein in data breach exposure

Services Australia may get powers to rein in data breach exposure

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?