Title : Cerulean Studios Trillian UTF-8 Word Wrap Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-2246 CVE ID : CVE-2007-3305
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-06-19
Technical Description
A vulnerability has been identified in Cerulean Studios Trillian, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a heap overflow error when processing word-wrapping UTF-8 strings, which could be exploited by remote attackers to crash an affected application or execute arbitrary code by sending a specially crafted message to a user (e.g. via the MSN protocol).