Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Advisories

May 22nd, 2008, 09:45 GMT · By Bogdan Popa

Vulnerabilities Detected in Trillian, Update Required

SHARE:

Adjust text size:


Trillian in action
Enlarge picture
Trillian is one of the most popular instant messaging clients namely thanks to the fact that it supports multiple instant messaging protocols, including Yahoo
Messenger, MSN Messenger, Jabber and many others. However, users of Trillian are advised to update the application as soon as possible to the latest version of the program due to several vulnerabilities found in previous releases, Secunia wrote in a notification published today. No less than three security glitches were discovered in Trillian, all of them allowing a potential attacker to compromise the affected system.

Here are the three security vulnerabilities explained by Secunia:

"A boundary error within the header parsing code for the MSN protocol can be exploited to cause a stack-based buffer overflow via a specially crafted X-MMS-IM-FORMAT header with an overly long attribute."

"An error within the XML parsing in talk.dll can be exploited to cause a memory corruption via certain malformed attributes within an 'IMG' tag."

"A boundary error when parsing messages (e.g. via the AIM network) with overly long attribute values within the FONT tag can be exploited to cause a stack-based buffer overflow."


All the three vulnerabilities allow the execution of arbitrary codes but only the last one requires the attacker to lure vulnerable users into opening a malicious picture that could permit him to compromise their computers.

As mentioned, the update to Trillian 3.1.10.0 is the only way to stay on the safe side and avoid a potential exploit of the security glitches reported today by Secunia. Moreover, note that both Trillian Basic and Trillian Pro are affected by the glitches. If you wish to download the latest versions of Trillian Basic and Pro, you can find both of them on our Windows download section, right here, on Softpedia.

TELL US WHAT YOU THINK:

2,397 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Take Your Desktop With You! With U3 Smart Drives

Yahoo Messenger Powerful Alternatives

Trillian also has security problems

Trillian in Trouble, Security Patch Required

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM