Trillian XML parser buffer overflow

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



See attached file.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Problem:
It is possible to create a skin for trillian that will trigger a buffer overflow.

In trillian.xml under the <prefs> section.
  [control name="colors" type="colors"]
   [colors  file="(4096 characters)"]

Still no word from Cerulean Studios on when a fix will be available. They were alerted to this 
problem on july 28th.

John C. Hennessy
Information security analyst



-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com>

iQA/AwUBPXCoUzfHYhhTZOYaEQKcNgCaAoKdMpf6ZGW10zDIT2G23qGPUiYAn10w
TNFv8B0VbJD/M8HVliA5B64V
=bYD6
-----END PGP SIGNATURE-----

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux