also @ TechSpot: Is Apple's USB wall adapter really worth $29?

Critical update for Trillian released

By

On June 19, 2007, 11:08 AM EST

Following the discovery of a fairly severe security flaw, the popular conglomerate messaging suite, Trillian, has been updated. Yesterday, Cerulean Studios released version 3.1.6.0 of the program, which is available for download already. The flaw was initially noticed back in May, but was not made public until recently.

Like many flaws of this nature, it can lead to code execution and ultimately system compromise:

Exploitation of this vulnerability could allow remote attackers to execute arbitrary code with the credentials of the currently logged on user.
Exploitation occurs simply by viewing a malicious message that contains a specially constructed UTF-8 string.

Whether or not people have been affected by this flaw isn't posted on the Trillian blog. If you are using a 3.x branch of Trillian you should update when you can.

No tags on this story

Post a new comment

Guest user

To post as an anonymous
user click here
.

Members

If you are a TechSpot member,
please login first.


By signing up you gain complete access to the TechSpot community. Join thousands of computer and technology enthusiasts that contribute and share knowledge in our forum. Post messages, get a private inbox, upload your own photo gallery and more.

Subscribe to TechSpot

Get free exclusive content, learn about new features and tech breaking news.