CVE-2007-2479
Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which generates a malformed response that is not truncated by a newline, which…
Does this matter?
Lower severity and a low EPSS score (2.54%). Track it; it rarely justifies an emergency change on its own.
Description
Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which generates a malformed response that is not truncated by a newline, which can cause portions of a server message to be sent to the attacker.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.54% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- cerulean studios/trillian
- Source
- cve@mitre.org
References
- http://blog.ceruleanstudios.com/?p=131Broken Link
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=522Broken Link
- http://osvdb.org/35722Broken Link
- http://secunia.com/advisories/25086Third Party Advisory
- http://www.securityfocus.com/bid/23730Third Party Advisory
- http://www.securitytracker.com/id?1017982Third Party Advisory
- http://www.vupen.com/english/advisories/2007/1596Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33983
- http://blog.ceruleanstudios.com/?p=131Broken Link
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=522Broken Link
- http://osvdb.org/35722Broken Link
- http://secunia.com/advisories/25086Third Party Advisory
- http://www.securityfocus.com/bid/23730Third Party Advisory
- http://www.securitytracker.com/id?1017982Third Party Advisory
- http://www.vupen.com/english/advisories/2007/1596Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33983
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.