First published: Tue Dec 31 2002(Updated: )
Buffer overflow in the XML parser of Trillian 0.6351, 0.725 and 0.73 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a skin with a long colors file name in trillian.xml.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cerulean Studios Trillian | =0.6351 | |
Cerulean Studios Trillian | =0.73 | |
Cerulean Studios Trillian | =0.725 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2366 has a high severity rating due to the potential for remote code execution and denial of service.
To fix CVE-2002-2366, users should upgrade to a later version of Trillian that addresses this buffer overflow vulnerability.
CVE-2002-2366 affects Trillian versions 0.6351, 0.725, and 0.73.
CVE-2002-2366 allows remote attackers to cause a denial of service and potentially execute arbitrary code.
The XML parser of Trillian is the component that is vulnerable in CVE-2002-2366.