Korean
<< Back
VID 23192
Severity 40
Port 139,445
Protocol TCP
Class P2P
Detailed Description A version of Trillian program which is older than 3.1.5.1 has been installed on the host. Trillian is a peer-to-peer (P2P) file sharing program for Microsoft Windows operating system used to share audio, video, and other media files. Cerulean Studios Trillian Pro versions prior to 3.1.5.1 are vulnerable to a heap-based buffer overflow vulnerability in the Rendezvous / Extensible Messaging and Presence Protocol (XMPP) component (plugins\rendezvous.dll). A remote attacker could exploit this vulnerability to execute arbitrary code on the affected host.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://dvlabs.tippingpoint.com/advisory/TPTI-07-06
http://www.securityfocus.com/archive/1/archive/1/467439/100/0/threaded
http://blog.ceruleanstudios.com/?p=131

* Platforms Affected:
Cerulean Studios, Trillian Pro versions prior to 3.1.5.1
Microsoft Windows Any version
Recommendation If P2P file sharing is not allowed at your organization, uninstall the Trillian program.

-- OR --

Upgrade to the latest version of Trillian (3.1.5.1 or later), available from the Trillian Web site at http://www.ceruleanstudios.com/
Related URL CVE-2007-2418 (CVE)
Related URL 23781 (SecurityFocus)
Related URL 34059 (ISS)