Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Heap-based buffer overflow in Cerulean Studios Trillian 3.x before 3.1.6.0 allows remote attackers to execute arbitrary code via a message sent through the MSN protocol, or possibly other protocols, with a crafted UTF-8 string, which triggers improper memory allocation for word wrapping when a window width is used as a buffer size, a different vulnerability than CVE-2007-2478.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Trillian文字换行UTF-8编码字符串堆溢出漏洞
Vulnerability Description
Trillian是一个聊天程序,和多种即时通讯程序使用相同的接口,包括AIM、ICQ、Yahoo! Messenger、MSN Messenger和IRC。 Trillian在处理畸形的UTF-8编码数据时存在漏洞,远程攻击者可能利用此漏洞控制用户机器。 Trillian没有正确地处理UTF-8序列,在对UTF-8文本执行文字换行时,错误的将窗口的宽度用作了缓冲区大小的值,因此可能会触发堆溢出。如果用户在聊天客户端中浏览了包含有特制UTF-8字符串的恶意消息的话,就可能触发这个溢出,导致执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A