Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credentials via a man-in-the-middle attack with a spoofed SSL certificate.
References
Link Resource
http://secunia.com/advisories/35620 Broken Link
http://www.securityfocus.com/archive/1/504573/100/0/threaded Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/35509 Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/51400 Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2010-04-29T19:00:00

Updated: 2018-10-10T18:57:01

Reserved: 2010-04-29T00:00:00


Link: CVE-2009-4831

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2010-04-29T19:30:00.370

Modified: 2022-02-07T18:17:30.943


Link: CVE-2009-4831

JSON object: View

cve-icon Redhat Information

No data.

CWE