CVE-2004-2370: Buffer Overflow
Published Dec 31, 2004
·Updated
Stack-based buffer overflow in Trillian 0.71 through 0.74f and Trillian Pro 1.0 through 2.01 allows remote attackers to execute arbitrary code via a Yahoo Messenger packet with a long key name.
Affected Software
13 affected components
Cerulean Studios Trillian Pro=2.0
Cerulean Studios Trillian=0.71
Cerulean Studios Trillian Pro=2.01
Cerulean Studios Trillian=0.74b
Cerulean Studios Trillian=0.74g
Cerulean Studios Trillian Pro=1.0
Cerulean Studios Trillian=0.74e
Cerulean Studios Trillian=0.73
Cerulean Studios Trillian=0.725
Cerulean Studios Trillian=0.74c
Cerulean Studios Trillian=0.74f
Cerulean Studios Trillian=0.74
Cerulean Studios Trillian=0.74d
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Aug 16, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2370?
CVE-2004-2370 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2004-2370?
To address CVE-2004-2370, it is recommended to update to the latest version of Trillian or Trillian Pro that is not affected by the vulnerability.
3
Which versions of Trillian are affected by CVE-2004-2370?
CVE-2004-2370 affects Trillian versions 0.71 through 0.74f and Trillian Pro versions 1.0 through 2.01.
4
Can CVE-2004-2370 be exploited remotely?
Yes, attackers can exploit CVE-2004-2370 remotely by sending a specially crafted Yahoo Messenger packet.
5
What type of vulnerability is CVE-2004-2370?
CVE-2004-2370 is a stack-based buffer overflow vulnerability.