CVE-2004-2304: Buffer Overflow
Integer overflow in Trillian 0.74 and earlier, and Trillian Pro 2.01 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2304?
CVE-2004-2304 is classified as a medium severity vulnerability that can lead to denial of service and potential arbitrary code execution.
How do I fix CVE-2004-2304?
To fix CVE-2004-2304, upgrade to a version of Trillian later than 0.74 or Trillian Pro later than 2.01.
What impact does CVE-2004-2304 have on affected software?
CVE-2004-2304 allows remote attackers to exploit the software, causing a denial of service and possibly executing arbitrary code.
Which versions of Trillian are affected by CVE-2004-2304?
CVE-2004-2304 affects Trillian versions 0.74 and earlier and Trillian Pro versions 2.01 and earlier.
What type of attack does CVE-2004-2304 facilitate?
CVE-2004-2304 facilitates a heap-based buffer overflow attack through a crafted directIM packet.