Trillian Vulnerabilities Open to Remote Exploitation

May 2, 2007

Three flaws affecting the Trillian IM chat application that could lead to remote exploitation by hackers are fixed in new Trillian version.

Cerulean Studios has patched multiple vulnerabilities in its popular chat application that could have been exploited remotely by attackers.

Cerulean Studios are the makers of Trillian, an instant messaging consolidation application that supports IRC, ICQ, AIM and MSN protocols. In its latest version of Trillian, the company fixed three vulnerabilities in the IRC (Internet Relay Chat) module that could have been exploited remotely and given attackers the ability to intercept private conversations or execute code, security researchers at iDefense Labs reported.

Researchers at IM security provider Akonix Systems said the number of malicious code attacks over IM networks is on the rise. Akonix tracked 38 such attacks during April, including IM worms such as Pykse, Samo and Tiotua.

"Malware continues to be released through IM networks, and is on the rise again for the first time since January," said Don Montgomery, vice president of marketing at Akonix. "Businesses cannot ignore the liabilities and potential damage they are opening themselves up to with unmanaged IM applications and networks."

According to iDefense, it is possible to cause the Trillian IRC client to return a malformed response to the server when handling long CTCP PING messages with UTF-8 characters. "This malformed response is truncated and is missing the terminating newline character," the iDefense advisory states. "This could allow the next line sent to the server to be improperly sent to an attacker."

In addition, whenever a user highlights a URL in an IRC message window, the chat application copies that data and places it in an internal buffer. If the URL contains a long string of UTF-8 characters, it is possible to overflow a heap-based buffer, corrupt memory and open the door for code execution, iDefense officials stated.

The final flaw allows a heap overflow to be triggered remotely when the IRC module receives a message that contains a font face HTML tag with the face attribute set to a long UTF-8 string. iDefense warns that attackers could use this vulnerability to intercept private communications for Trillian IRC users or execute code with the credentials of the currently logged on user.

The vulnerabilities affect Cerulean Studios Trillian 3.1, and have been addressed in Trillian version 3.1.5.0.

Copyright 2007 by Ziff Davis Media, Distributed by United Press International


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - not rated yet


May 2, 2007 all stories

Comments: 0

not rated yet
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Interoperability overdue for instant messaging
    created Oct 15, 2009 | popularity not rated yet | comments 0
  • Google Announces the Google Pack
    created Jan 08, 2006 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

Other News

Panasonic Develops High Energy Lithium-ion Battery Module  with High Reliability

Panasonic plans home-use storage cell

Technology / Energy

created Dec 23, 2009 | popularity 4 / 5 (18) | comments 9

Panasonic Corp., which recently made a successful takeover bid for Sanyo Electric Co., plans to market a lithium-ion storage cell for home use around fiscal 2011.


Taiwan has unveiled what it calls Asia's biggest solar power plant

Taiwan unveils Asia's biggest solar plant: govt

Technology / Energy

created Dec 23, 2009 | popularity 3.3 / 5 (6) | comments 3

Taiwan has unveiled what it calls Asia's biggest solar power plant as the island, which imports almost all its energy, seeks to tap into clean renewable resources, the government said Wednesday.


Comcast settles data discrimination lawsuit

Technology / Internet

created Dec 23, 2009 | popularity not rated yet | comments 2

(AP) -- Comcast will pay up to $16 million to settle a class-action lawsuit accusing the cable TV operator of delaying certain Internet traffic.


A man uses a laptop computer at a wireless cafe

China cracks down on online games: report

Technology / Internet

created 10 hours ago | popularity not rated yet | comments 0

China has placed more than 4.65 million computers at some 80,000 Internet cafes under watch in a bid to crack down on violent or pornographic online games, state media reported Friday.


NORAD is tracking Santa Claus's progress

Follow Santa Claus, courtesy Google and NORAD

Technology / Internet

created Dec 24, 2009 | popularity 3.4 / 5 (5) | comments 0

Santa Claus is coming to your town -- and NORAD is tracking him as he drops off presents around the world. The North American Aerospace Defense Command, which monitors the North American airspace, on Thursday ...