Format string vulnerability in the error handling of IRC invite responses for Trillian 0.725 and 0.73 allows remote IRC servers to execute arbitrary code via an invite to a channel with format string specifiers in the name.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/9761.php | vdb entry |
http://www.securityfocus.com/archive/1/285695 | mailing list |
http://www.securityfocus.com/bid/5388 | vdb entry |