Trillian is een multiprotocol instantmessagingclient voor Windows. Hiermee kunnen berichten uitgewisseld worden via verschillende im-netwerken, zoals MSN, Yahoo, AIM, ICQ en IRC. Het programma wordt in twee smaken uitgebracht, namelijk Basic en Pro. De Basic-smaak is gratis en bevat alle standaard componenten die je van een im-programma mag verwachten. De Pro-variant gaat voor een slordige 25 dollar over de virtuele toonbank en bevat meer mogelijkheden, zoals ondersteuning voor videochat, Jabber, Novell GroupWise Messenger, Rendezvous en het gebruikmaken van plugins. Een compleet overzicht van de verschillen tussen de twee smaken is op deze pagina te bewonderen. De ontwikkelaars hebben onlangs versie 3.1.6.0 uitgebracht met de volgende aankondiging:
Trillian 3.1.6.0
iDefense Labs has notified us of a security vulnerability in Trillian 3.x, and we worked last week to resolve it and issue a patch. Details will shortly be live at the following url. You'll find the latest full version available here, and existing customers should be receiving an auto-update notification upon their next restart of Trillian. We recommend all users upgrade to the latest version.
Thanks!
Version 3.1.5.1:
As mentioned in the last blog, we fixed 4 vulnerabilities in Trillian 3.1 with our new 3.1.5.1 release. The links to the specific advisories are below:ZDI-CAN-169: Trillian Pro Rendezvous XMPP HTML Decoding Heap Corruption Vulnerability
All of these vulnerabilities have been addressed in version 3.1.5.1 and we encourage everyone to upgrade to the latest version. We will be rolling out an auto-update for our existing customers shortly.
iDefense: Trillian Multiple IRC Vulnerabilities
Special thanks to both the ZDI and iDefense teams for their assistance in reporting and resolving these issues; we've worked with a handful of vulnerability research firms in the past, and I can happily say that these folks are both top-notch researchers and extremely professional. We look forward to continuing our relationship with them both to ensure we bring you the most secure and error-free software possible![break]