Trillian does not check SSL certificate before sending MSN user credentials. An attacker is able to obtain MSN username and password with a spoofed certificate and no alert is generated to the user. This vulnerability was found in Trillian Basic 3.1. Other versions and/or protocols may also be affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/78684/trillian-ssl.txt
Source: https://packetstormsecurity.com/files/78684/Trillian-SSL-Certificate-Vulnerability.html