Security Flaw Uncovered in Trillian

By Nate Mook | Published March 25, 2005, 1:13 PM

A potential security vulnerability has been discovered in Trillian, an alternative instant messaging client created by Cerulean Studios that supports AIM, ICQ, MSN and Yahoo IM networks. The flaw involves a buffer overflow that could be exploited to gain control of a Trillian user's PC.

LogicLibrary, maker of software development tools, says its BugScan application uncovered the buffer iteration overflow in Trillian's handling of HTTP 1.1 response headers. The vulnerability has existed within several of Trillian's plug-in components since version 2.0, but was mostly eliminated with the release of Trillian 3.

However, Trillian 3.1 still contains two overflow bugs in the Yahoo Messenger component, LogicLibrary says. The problem can be used to shut down Trillian or lead to arbitrary code being executed on a vulnerable computer.

"In order to build trust and confidence in the quality of today’s software, LogicLibrary believes it’s crucial that vendors work closely together to fix problems and provide the public with as much information as possible," said LogicLibrary general manger Ralph Massaro.

Cerulean Studios downplayed the significance of the flaw, saying the risk is extremely low for a real world attack. Nonetheless, the company plans to correct the buffer overflows in its next release of Trillian.

Comments

View comments by with a score of at least

I have not used Trillian, and barely even know what it is...nevertheless I find the title of this article is misleading, and wanted to point it out. Look at the title. Now look at the first sentence in the article. Find a "potential" inconsistency here?

Score: 0

|

Wow... Spread the news even more than it was before.. Now more people can try to obtain access to many more people..

Besides.. I still dislike Trillian.. It's nice but is still buggy when having file transfers and other things..

Score: 0

|

"Cerulean co-founder and CEO Scott Werndorfer said the buffer-related vulnerability is of "extremely low risk." In an e-mail sent to CNET News.com on Friday, he said that attackers would need to construct an entire fake IM software client for the sole purpose of sending a malicious request to a Trillian user. That person would then have to actually accept that message request in order for the attacker to take advantage of the flaw, he said."

endquote

like many other alleged threats, this one involves user stupidity, not program flaws. The user has to accept accept a message request. so unless you know who you are talking to dont be a lamer and talk to strangers :)

Score: 0

|

if the flaw wasn't a major issue of windows then none of the apps would be experiencing it.

lets deflect blame here and point fingers at alllll the apps as they start becoming exploited through a windows bug, not an application bug.

the applications cannot create holes where holes don't exist. they simply are made using the flawed windows API

Score: 0

|

Thanks Viking for the link... provides a bit more explanation of the problem.

Score: 0

|

Looks like it only affects the Yahoo Messenger component?

Score: 0

|

That is correct... but the fact still remains that the flaw does expose the computer to complete, remote control.

I'm not criticizing Trillian or anyone else in my posts... I'm just saying that people need to realize and understand that it's not just Microsoft that has these issues.

It's important that we keep ALL software up to date, and it's even more important that we all learn how to protect ourselves and teach others to protect themselves rather than start going off on companies for their imperfection.

Score: 0

|

For all those anti-MS people out there that claim the biggest security flaw for IE is ActiveX and its tight integration with the OS... here's evidence that such a claim is invalid.

"The flaw involves a buffer overflow that could be exploited to gain control of a Trillian user's PC." So you see, it doesn't have to be a part of the OS in order to give user control over the PC. It can be done just fine without such integration.

Score: 0

|

But they will fix the flaw in a couple of days Not weeks or month's unlike M$ ......

Score: 0

|

Stop saying M$. It just makes you seem like an 8 year old wannabe, to fit in with the "cool crowd".

Score: 0

|

Yes however a buffer overflow in trillian does not compromise your self down to the core of the OS.

Score: 0

|

ha! .. so true

nothing wrong with Microsoft or $$$...

i wish id created a corporation like microsoft.. then i could feel bad for those who programmatically spew anti-Microsoft rhetoric trying to destroy what they could not create

Score: 0

|

That remains to be seen. They haven't released a fix, nor have they indicated timing on release of a fix, so don't make such a statement yet.

As for the other individual's rhetoric about it not being compromised down to the OS, that's obviously not true since the article clearly states that the flaw would give them remote control of the system.

Score: 0

|

The article said it would be fixed for Trillian's next release, which would be 3.2 actually. That being said, I believe it's around another month before this version actually gets released, even into Beta form.

Score: 0

|

Yes, it is every little boy's dream to create abusing monopoly, stifle innovation and force subpar products down everyone's throats.

Score: 0

|

No, it's not that... it's about creating products and services that people actually use and making a profit off those products and services. It's called capitalism.

Now let's stick to the topic please... this thread is about the security issues of Trillian, not about economic and business practices.

Score: 0

|

> it's about creating products and services that
> people actually use and making a profit off those
> products and services. It's called capitalism.

And is nothing like Microsoft's abusing monopoly.

Score: 0

|

Microsoft isn't forcing their products down anyones throats. You have a choice over everything on your computer these days.

And the products are in no-way sub-par, they're top of the line actually.

Score: 0

|

Now repeat after me: Monopoly means all the consumers have no other choice. No-other-choice.

Write it down somewhere. I dunno, a yellow post-it on top of your monitor or something.

Score: 0

|

Monopoly is a legal term and Microsoft is a convicted monopoly both in US (DoJ vs Microsoft) and in Europe (EC vs Microsoft). Don't bother repeating, it is beyond your comprehension abilities.

Score: 0

|

Just like returning to the topic of discussion for this article is beyond your comprehension.

Seriously, let it go already. You've made your point but no one else cares, because we are more concerned at this time with security in instant messenger clients like Trillian, Yahoo, etc.

Score: 0

|

Yes, great care for Trillian security must compel you to repeatedly attack one side of lengthy off topic discussion. Go play with other kids.

Score: 0

|

Ya, they don't force anything down my throat. I left IE for FireFox, OE for ThunderBird, MS Office for OpenOffice, and then think about anythign else that might be non-MS, but still pay for is mostly all free (to list a few, GIMP, NVU, FileZilla, OpenVPN, etc.)

I do not like MS, but guess they know how to make money and so far haven't seen them stop or stiffle any building for GNU and GPL lincense software :D

Score: 0

|

I think if you dont wish to discuss an issue mister 2.30 poster, dont bring it into the topic.
While any vunerability is worrying I,m glad to note that thus far this is in the realms of the "paper" hack.
I place great emphasis on the word "Potential".

Score: 0

|

I can't believe that Betanews hasn't just created a normal Forum where this crap gets redirected too. This is just silly. Same with files. people have to rate a file to make some comments. There should be the normal rating with small coments section, and a forum discussion link for blabbing and experiences and "program x is better" junk.

Cmon guys! :)

Score: 0

|

Europe said Microsoft was a "near monopoly". Even they didn't have the chutzpah to tell the biggest lie ever told in the software business.

Repeat after me ... Microsoft was not and never was a monopoly.

Score: 0

|

They don't force anything down anyone's throat. Don't use a PC if you don't like Microsoft. That simple. Or move to Linux or a Mac. Quit whining.

Or you could go program your own OS and make all the need programs ported over to your OS. GG.

Score: 0

|

Actually, half the posters in this article are blaming MS or talking about MS. Get a clue. I'm tired of listening to whiny emo's complaining about Microsoft. Quit trying to be "original" and "unique". You're in fact forcing your ill-backed opinions and accusations down MY throat.

Score: 0

|

Security firm: Windows patches not responsible for 'Black Screen of Death'

On second thought, maybe that access control list thingie with the lockdown something-or-rather didn't trigger an alleged, perhaps non-existent, pandemic.

Windows desktops and notebooks reach near price-performance parity for Holiday 2009

Gone are the days when average Windows desktop offered more for less than laptops.

Latest Firefox 3.6 beta fixes 133 bugs, promises faster page load times

A once-sluggish beta testing process has kicked into overdrive, with astonishing success at finding serious bugs. Will Mozilla be able to fix all the others in time?

Confirmed: Office 2010 to ship in June

Two weeks after Microsoft had been expected to draw a clearer roadmap for its principal applications suite, it's finally ready to commit to the end of H1.

Apple settles with Psystar except for 'circumvention devices'

The fracas with the Florida clone computer maker might have ended today had Apple not have muddled the issue over a cheap piece of Psystar software.

Microsoft denies latest 'Black Screen of Death' claims

After an anti-malware producer announced a fix to what it says is a swarm of recent KSoD problems, evidence of the swarm itself has yet to turn up.

New EU antitrust commissioner will oversee Microsoft, Oracle+Sun, Intel issues

As one of Europe's most prominent politicians shifts positions in January, her replacement remains a question mark over technology's biggest issues.

Without its own 'iTablet' yet, is Apple missing the boat?

Steve Jobs is on record as dissing "single-purpose" devices like e-readers. But given their recent popularity, was that a mistake?

Not-so-mobile battery life: Time to force the issue

Carmi Levy | Wide Angle Zoom: If power efficiency is important when you buy a car or even a motorcycle, why shouldn't it matter for a smartphone?

Apple invokes DMCA, claims Psystar is 'trafficking in circumvention devices'

In trying to close the book on possibly the last attempt at a Mac clone, Apple cites from its own landmark case...but may actually be misinterpreting it.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?