CVE-2002-2155: High severity Cerulean Studios Trillian vulnerability
Published Dec 31, 2002
·Updated
Format string vulnerability in the error handling of IRC invite responses for Trillian 0.725 and 0.73 allows remote IRC servers to execute arbitrary code via an invite to a channel with format string specifiers in the name.
Affected Software
2 affected components
Cerulean Studios Trillian=0.73
Cerulean Studios Trillian=0.725
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Nov 16, 2005
CVE Published
via MITRE·09:17 PM
Data Sourced
via MITRE·09:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2155?
CVE-2002-2155 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2002-2155?
To fix CVE-2002-2155, upgrade to a version of Trillian that is not vulnerable, specifically versions above 0.73.
3
What versions of Trillian are affected by CVE-2002-2155?
CVE-2002-2155 affects Trillian versions 0.725 and 0.73.
4
How does CVE-2002-2155 exploit work?
CVE-2002-2155 exploits a format string vulnerability in the error handling of IRC invite responses.
5
What are the potential consequences of CVE-2002-2155?
The consequences of CVE-2002-2155 may include arbitrary code execution on the vulnerable computer.