No. 1 Story

HP job cuts loom for Australian employees

A number of Australian employees of Hewlett-Packard are facing the loss of their jobs as the global computer giant looks to slash its worldwide workforce by up to 30,000.

read more

Related Articles

Adoption of cloud computing has reached a tipping point  - but don’t expect legacy...
In yet another blow to the Facebook IPO this week, following the withdrawal of...
Recruitment technology and social media have played a significant role in growing business in...
Those elusive pocket monsters, the Pokémon are becoming more numerous.  Nintendo announce two new...
Fancy a 4G Windows Phone? Your wait may be over next Tuesday when Telstra...

Trillian chat client gets critical update

Your IT - Home IT

The Trillian multi-protocol chat client has been updated to eliminate a vulnerability that could result in the execution of arbitrary code.

Rated as "critical" by FrSIRT (the French Security Incident Response Team) and "highly critical" by Secunia, the flaw has been fixed in Trillian 3.1.6.0, released this week.

The problem stems from the incorrect use of the window width as the buffer size when wrapping UTF-8 strings, according to iDefense. A maliciously constructed message can cause heap corruption, resulting in the execution of code contained within that message.

Although iDefense confirmed the vulnerability only in version 3.1.5.1, earlier releases may share the same problem.

The new version can be downloaded via developer Cerulean Studios' web site. Existing Trillian users will be prompted to update when they next use the program.

Trillian supports the AIM, ICQ, MSN, Yahoo Messenger, and IRC chat protocols, allowing Windows users to connect to multiple networks (and even establish multiple sessions on one network) from a single client. The $US25 Pro version adds video chat and support for Jabber (as used by Google Talk), GroupWise Messenger, and Rendezvous (for iChat AV compatibility), plus other features.