CVE-2007-2479

Description

Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which generates a malformed response that is not truncated by a newline, which can cause portions of a server message to be sent to the attacker.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
1.447

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Trillian 3.1Windows
Vulnerabilities CVE-2007-2479,CVE-2009-4831 are affected in Trillian 3.1Windows
Multiple vulnerabilities affected in Trillian 3.1 (For Ubuntu)Linux
Multiple vulnerabilities affected in Trillian 3.1 (For Debian)Linux
Multiple vulnerabilities affected in Trillian 3.1 (For Centos)Linux
Multiple vulnerabilities affected in Trillian 3.1 (For RedHat)Linux
Multiple vulnerabilities affected in Trillian 3.1 (For Suse)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234