Multiple flaws detected in Cerulean Studios IM software

By
Follow google news

Multiple vulnerabilities have been discovered in Cerulean Studios instant messaging software, Trillian, which could be exploited by a malicious attacker to steal personal data and compromise an affected computer.

Multiple flaws detected in Cerulean Studios IM software
Trillian is a popular chat application that supports the IRC, ICQ, AIM and MSN protocols. Remote exploitation of the flaw in the IRC module of the software could allow an attacker to intercept private conversations and execute arbitrary code as the currently logged on user.

Another of the vulnerabilities is caused by an error in the way the tool handles long CTCP PING messages, which can be used to cause a vulnerable user to inadvertently send sensitive information to the hacker. A heap overflow error causes another flaw when highlighting long URLs, which can be exploited by remote attackers to execute arbitrary code.

The flaws affect Cerulean Studios Trillian version 3.1. The US-based software company has addressed the bugs within version 3.1.5.0.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?