Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

ADVISORIES

Trillian in Trouble, Security Patch Required

- Vulnerability found in the IM application

By: Bogdan Popa, Security and Search Engines Editor

Trillian is an application installed on lots of computers around the world for the simple reason that it allows users to communicate on the most popular instant
messaging networks with a single software instance. Imagine that you have friends on Google Talk, MSN Messenger, Yahoo Messenger and ICQ. Keeping four applications in the System Tray isn't quite the most convenient thing to do, so starting a single program that would provide all the functions of the four tools is the best solution. Yes, I know, there are several other similar applications out there, but today we're talking about Trillian and its security flaw.

And because we're on the Trillian vulnerability subject, find out that SecurityFocus has reported an "overly long nickname remote DoS vulnerability" in Trillian which may allow an attacker crash somebody's IM instance. According to the advisory, the issue affects both Trillian 3.1 and Trillian Pro 3.1, but other versions may be affected as well.

"Trillian is prone to a remote denial-of-service vulnerability because it fails to sufficiently bounds-check user-supplied data. Few details regarding this vulnerability are available; we will update this BID when more information emerges. Exploiting this issue allows remote attackers to trigger denial-of-service conditions, denying further service to legitimate users," SecurityFocus wrote in the advisory.

At this time, there's no security patch, fix or update available on the web so extra-care is recommended when using the Trillian versions mentioned above.

Trillian was quite a popular application in the past but, Cerulean Studios are preparing a new version of the program, codename Astra, which is supposed to bring lots of new functions to its users. At this time, the new flavor is only available in alpha stages so only a limited number of users are able to test it.

MORE RELATED ARTICLES: Your Computer... On a Stick - Part I Bye Bye Yahoo Messenger, Here Comes Trillian for Mac OS X! Yahoo Messenger or Another Compatible Software? Yahoo Messenger Still Unpatched, Users at Risk! Yahoo Messenger Alternative? No Thanks, I Choose YM!
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:


25th April 2008, 08:56 GMT | Copyright (c) 2008 Softpedia | Contact:
Read by 574 user(s) | Rating: | 7 vote(s) so far | Cast your vote:
Trillian in Trouble, Security Patch Required - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT Trillian in Trouble, Security Patch Required

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive