CVE-2007-2479
Last modified
CVE-2007-2479 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which generates a malformed response that is not truncated by a newline, which can cause portions of a server message to be sent to the attacker.. EPSS estimates a 2.54% chance of exploitation in the next 30 days.
Description
Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which generates a malformed response that is not truncated by a newline, which can cause portions of a server message to be sent to the attacker.
Metrics
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cerulean Studios | Trillian | 3.1 |
References
- http://blog.ceruleanstudios.com/?p=131Broken Link
- http://osvdb.org/35722Broken Link
- http://secunia.com/advisories/25086Third Party Advisory
- http://www.securityfocus.com/bid/23730Third Party Advisory
- http://www.securitytracker.com/id?1017982Third Party Advisory
- http://blog.ceruleanstudios.com/?p=131Broken Link
- http://osvdb.org/35722Broken Link
- http://secunia.com/advisories/25086Third Party Advisory
- http://www.securityfocus.com/bid/23730Third Party Advisory
- http://www.securitytracker.com/id?1017982Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2479?
How severe is CVE-2007-2479?
How do I fix CVE-2007-2479?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-2473SQL injection vulnerability in stylesheet.php in CMS Made Si…
- CVE-2007-2474Multiple PHP remote file inclusion vulnerabilities in Turnke…
- CVE-2007-2475Unspecified vulnerability in the ADSCHEMA utility in Novell …
- CVE-2007-2476Unspecified vulnerability in Novell SecureLogin (NSL) 6 SP1 …
- CVE-2007-2477PHP remote file inclusion vulnerability in phpMyChat.php3 in…
- CVE-2007-2478Multiple heap-based buffer overflows in the IRC component in…
- CVE-2007-2480The _udp_lib_get_port function in net/ipv4/udp.c in Linux ke…
- CVE-2007-2481PHP remote file inclusion vulnerability in wordtube-button.p…
- CVE-2007-2482Directory traversal vulnerability in wordtube-button.php in …
- CVE-2007-2483Directory traversal vulnerability in js/wptable-button.php i…
- CVE-2007-2484PHP remote file inclusion vulnerability in js/wptable-button…
- CVE-2007-2485PHP remote file inclusion vulnerability in myflash-button.ph…
Are you affected by CVE-2007-2479?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
