Computing in the real world
SEARCH FOR: IN:
      
Welcome Guest  Register Log in

News 

[PSUs]
Wednesday 26th October 2005
Critical security vulnerability found in Skype 10:26AM, Wednesday 26th October 2005
A highly critical security vulnerability has been discovered in various flavours of the Skype IP telephony software.

A boundary error exists when handling Skype-specific URI types such as 'callto://' and 'skype://'. This can be exploited to cause a buffer overflow and allows arbitrary code execution when the user clicks on a specially-crafted Skype-specific URL.

According to Secunia, the vulnerability is related to a boundary error in the handling of VCARD imports. It can be exploited to cause a buffer overflow and allows arbitrary code execution when the user imports a specially-crafted VCARD. There can also be annother boundary error in the handling of certain unspecified Skype client network traffic, which can be exploited to cause a heap-based buffer overflow. For more information go to secunia.com/advisories/17305/.

Users of Skype for Linux, Mac OS X, Pocket PC and Windows should update to the latest version at www.skype.com/download.

Submit to: Digg  |  Slashdot  |  Del.icio.us  |  Technorati

Related News



Top 10 Broadband

150+ broadband packages

Compare 30+ mobile broadband deals

Powered by Top 10 Broadband


Columns

Prolog:

After eight years in a caring relationship, Tim Danton is falling for a desktop once again. › See full Opinion