CVE-2002-1486: Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1486?
CVE-2002-1486 has a high severity rating due to its potential for remote code execution and denial of service.
How do I fix CVE-2002-1486?
To fix CVE-2002-1486, users should upgrade to a patched version of Trillian beyond 0.74.
What versions of Trillian are affected by CVE-2002-1486?
CVE-2002-1486 affects Trillian versions 0.73, 0.725, and 0.74.
What types of attacks are possible with CVE-2002-1486?
CVE-2002-1486 allows for denial of service attacks and potentially arbitrary code execution through malicious IRC servers.
Is CVE-2002-1486 still relevant today?
While CVE-2002-1486 was identified over two decades ago, it remains relevant for systems that may still be running affected versions of Trillian.