SecurityAlert : 3849 CVE : CVE-2008-2008 SecurityRisk : Low (About) Remote Exploit : Yes Local Exploit : Yes Exploit Available : No Credit : Juan Pablo Lopez Yacubian Published : 03.05.2008
Affected Software :
Trillian 3.1
Advisory Content :
I found a flaw in the trillian 3.1 for Windows.
It is that on receipt of a nickname too long with some characters, this
leads to break the program, the failure of the curious is that when the
abri with ollydbg tries to read the argument of the message such as whether
to wear the nickname long special characters and message write many letters
"A" is the result
Access violation when reading [41414141]
The test is made using an account of MSN Messenger and I got a nick there
till the limit of characters to the next character "‿" (without the
quotes) and send a message to another account that had msn in trillian.
Anyway, is wrong with many more characters that is only one example ...
Greetings!
Juan Pablo Lopez Yacubian
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.