Multiple flaws detected in Cerulean Studios IM software

By

Multiple vulnerabilities have been discovered in Cerulean Studios instant messaging software, Trillian, which could be exploited by a malicious attacker to steal personal data and compromise an affected computer.

Multiple flaws detected in Cerulean Studios IM software
Trillian is a popular chat application that supports the IRC, ICQ, AIM and MSN protocols. Remote exploitation of the flaw in the IRC module of the software could allow an attacker to intercept private conversations and execute arbitrary code as the currently logged on user.

Another of the vulnerabilities is caused by an error in the way the tool handles long CTCP PING messages, which can be used to cause a vulnerable user to inadvertently send sensitive information to the hacker. A heap overflow error causes another flaw when highlighting long URLs, which can be exploited by remote attackers to execute arbitrary code.

The flaws affect Cerulean Studios Trillian version 3.1. The US-based software company has addressed the bugs within version 3.1.5.0.
Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Qantas facing 'significant' data theft after cyber attack

Qantas facing 'significant' data theft after cyber attack

Home Affairs officer accessed data on "friends and associates"

Home Affairs officer accessed data on "friends and associates"

Qantas contacted by "potential cyber criminal"

Qantas contacted by "potential cyber criminal"

SA Power Networks tackles IAM, cloud security under five-year strategy

SA Power Networks tackles IAM, cloud security under five-year strategy

Log In

  |  Forgot your password?