Overview
A vulnerability in Cerulean Studios Trillian Instant Messenger client may lead to execution of arbitrary code.
Description
| Cerulean Studios Trillian Instant Messenger client fails to properly handle specially crafted UTF-8 text. A heap overflow may occur when Trillian receives a messages with malformed UTF-8 strings. | 
Impact
| A remote, authenticated attacker may be able to execute arbitrary code with the privileges of the user or cause a denial-of-service condition by sending the client a message. | 
Solution
| Update Cerulean Studios has released an update to address this issue. See the Cerulean Studios Blog for more information. | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
This vulnerability was reported in iDefense Public Advisory 6.18.07. iDefense credits www.BlurredLogic.com with reporting this issue.
This document was written by Chris Taschner.
Other Information
| CVE IDs: | CVE-2007-2478 | 
| Severity Metric: | 6.08 | 
| Date Public: | 2007-06-18 | 
| Date First Published: | 2007-06-20 | 
| Date Last Updated: | 2007-06-29 16:18 UTC | 
| Document Revision: | 11 |