Get a Pentest and security assessment of your IT network.

Advisories

Zero Day Initiative Advisory 08-078

A vulnerability allows remote attackers to potentially execute arbitrary code on vulnerable installations of Cerulean Studios Trillian. Authentication is not required to exploit this vulnerability. The specific flaw exists within the XML processing code for Trillian. When parsing specially formulated xml, the application will corrupt an internal data structure. Whilst deallocating this data structure, the application can be tricked into freeing a single allocated chunk multiple times, which can potentially lead to code execution.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/72650/ZDI-08-078.txt

Source: https://packetstormsecurity.com/files/72650/Zero-Day-Initiative-Advisory-08-078.html

Related posts
Advisories

LynX-adv4_SignatureDB.txt

Advisories

Secunia Security Advisory 16497

Advisories

Secunia Security Advisory 19451

Advisories

Debian Linux Security Advisory 1187-1