AplusWebMaster
Topic Starter
FYI…
- http://preview.tinyurl.com/2ze7ls
July 17, 2007 (Computerworld) - "Security researchers (?) yesterday disclosed critical vulnerabilities in two popular Windows instant messaging clients, Yahoo Messenger and Trillian. The Yahoo Messenger bug, which was posted to the Full Disclosure mailing list Monday by Rajesh Sethumadhavan, is a buffer overflow flaw that can be exploited with a specially crafted address book entry. Messenger immediately crashes when it encounters the malformed entry, said Sethumadhavan, but it may also be susceptible to code execution, meaning an attacker might be able to inject his own malicious code – a keystroke stealer or a spam bot, for instance – into a compromised PC.
Yahoo Inc. has not posted a patch for the vulnerability; the company did not immediately respond to a request for confirmation and comment. Trillian, a multiservice client, also sports two bad bugs, said other researchers.
A trio made up of Nate Mcfeters, Billy "BK" Rios and Raghav "The Pope" Dube identified two vulnerabilities in Trillian's handling of the AIM URI (uniform resource identifier). According to Mcfeters, Rios and Dube, the Trillian flaws are similar to the Internet Explorer/Firefox vulnerability that raised a ruckus last week…"
- http://secunia.com/advisories/26086/
Release Date: 2007-07-17
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: Trillian Basic 3.x, Trillian Pro 3.x
…The vulnerabilities are confirmed in Trillian Basic 3.1.6.0. Other versions may also be affected.
Solution: Do not browse untrusted sites.
Disable the "aim://" URI handler…"
> http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-3833

- http://preview.tinyurl.com/2ze7ls
July 17, 2007 (Computerworld) - "Security researchers (?) yesterday disclosed critical vulnerabilities in two popular Windows instant messaging clients, Yahoo Messenger and Trillian. The Yahoo Messenger bug, which was posted to the Full Disclosure mailing list Monday by Rajesh Sethumadhavan, is a buffer overflow flaw that can be exploited with a specially crafted address book entry. Messenger immediately crashes when it encounters the malformed entry, said Sethumadhavan, but it may also be susceptible to code execution, meaning an attacker might be able to inject his own malicious code – a keystroke stealer or a spam bot, for instance – into a compromised PC.
Yahoo Inc. has not posted a patch for the vulnerability; the company did not immediately respond to a request for confirmation and comment. Trillian, a multiservice client, also sports two bad bugs, said other researchers.
A trio made up of Nate Mcfeters, Billy "BK" Rios and Raghav "The Pope" Dube identified two vulnerabilities in Trillian's handling of the AIM URI (uniform resource identifier). According to Mcfeters, Rios and Dube, the Trillian flaws are similar to the Internet Explorer/Firefox vulnerability that raised a ruckus last week…"
- http://secunia.com/advisories/26086/
Release Date: 2007-07-17
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: Trillian Basic 3.x, Trillian Pro 3.x
…The vulnerabilities are confirmed in Trillian Basic 3.1.6.0. Other versions may also be affected.
Solution: Do not browse untrusted sites.
Disable the "aim://" URI handler…"
> http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-3833