CVE-2007-2479
Last modified
CVE-2007-2479 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which generates a malformed response that is not truncated by a newline, which can cause portions of a server message to be sent to the attacker.. EPSS estimates a 2.54% chance of exploitation in the next 30 days.
Description
Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which generates a malformed response that is not truncated by a newline, which can cause portions of a server message to be sent to the attacker.
Metrics
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cerulean Studios | Trillian | 3.1 |
References
- http://blog.ceruleanstudios.com/?p=131Broken Link
- http://osvdb.org/35722Broken Link
- http://secunia.com/advisories/25086Third Party Advisory
- http://www.securityfocus.com/bid/23730Third Party Advisory
- http://www.securitytracker.com/id?1017982Third Party Advisory
- http://blog.ceruleanstudios.com/?p=131Broken Link
- http://osvdb.org/35722Broken Link
- http://secunia.com/advisories/25086Third Party Advisory
- http://www.securityfocus.com/bid/23730Third Party Advisory
- http://www.securitytracker.com/id?1017982Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2479?
How severe is CVE-2007-2479?
How do I fix CVE-2007-2479?
Are you affected by CVE-2007-2479?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
