CVE-2007-2418: Buffer Overflow
Published May 2, 2007
·Updated
Heap-based buffer overflow in the Rendezvous / Extensible Messaging and Presence Protocol (XMPP) component (plugins\rendezvous.dll) for Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to execute arbitrary code via a message that triggers the overflow from expansion that occurs during encoding.
Affected Software
2 affected components
Cerulean Studios Trillian Pro<=3.1.5.0
Cerulean Studios Trillian Pro<=3.1_build_121
Remediation
Patch Available
Event History
May 2, 2007
CVE Published
10:19 PM
May 3, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2418?
CVE-2007-2418 is classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2007-2418?
To fix CVE-2007-2418, upgrade Cerulean Studios Trillian Pro to version 3.1.5.1 or later.
3
What type of vulnerability is CVE-2007-2418?
CVE-2007-2418 is a heap-based buffer overflow vulnerability.
4
Which versions of Trillian Pro are affected by CVE-2007-2418?
CVE-2007-2418 affects Trillian Pro versions up to and including 3.1.5.0.
5
Can CVE-2007-2418 be exploited remotely?
Yes, CVE-2007-2418 can be exploited remotely through specially crafted messages.