Record summary

CVE-2002-1486 has a selected CVSS score of 7.5; EIP currently links 5 catalogued exploits.

Description

Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
5

Proofs of concept

5

Catalogued exploits

ExploitDBTrillian 0.6351/0.7x - Identd Buffer OverflowExploitDB exploitby Lance Fitz-HerbertNot analyzed1 file
ExploitDB

PoC details
ExploitDBTrillian 0.73/0.74 - IRC PRIVMSG Buffer OverflowExploitDB exploitby Lance Fitz-HerbertNot analyzed1 file
ExploitDB

PoC details
ExploitDBTrillian 0.73/0.74 - IRC JOIN Buffer OverflowExploitDB exploitby Lance Fitz-HerbertNot analyzed1 file
ExploitDB

PoC details
ExploitDBTrillian 0.725/0.73/0.74 - IRC User Mode Numeric Remote Buffer OverflowExploitDB exploitby Lance Fitz-HerbertNot analyzed1 file
ExploitDB

PoC details
ExploitDBTrillian 0.74 - IRC Oversized Data Block Buffer OverflowExploitDB exploitby Lance Fitz-HerbertNot analyzed1 file
ExploitDB

PoC details

References

12