The messages exchanged with this program are encrypted with the Blowfish algorithm and then converted to plain-text with Base64.
The problem is located just in the Base64 function because the program shows an alert dialog if there are illegal chars in a message (like % or _). After about 15 consecutive dialogs the program definitely crashs.
The vendor has released a new version without changing the version number (1.60). All the programs downloaded after the 20 September 2004 are not vulnerable.