Skype URI Handler Format String Bug Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1016966
|
|
SecurityTracker URL: http://securitytracker.com/id?1016966
|
|
CVE Reference: CVE-2006-5084
(Links to External Site)
|
Updated: Oct 4 2006
|
Original Entry Date: Oct 2 2006
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 1.5.0.79
|
Description: A vulnerability was reported in Skype. A remote user can execute arbitrary code on the target system.
A remote user can send specially crafted data to trigger a format string flaw and execute arbitrary code on the target system. Specially
crafted arguments passed to the Skype URI handler can trigger this flaw.
The original advisory is available at:
http://www.security-protocols.com/modules.php?name=N
ews&file=article&sid=3259
|
Impact: A remote user can execute arbitrary code on the target system.
|
Solution: The vendor has issued a fixed version of Skype for Mac (1.5.*.80 or later).
The vendor's advisory is available at:
http://www.skype.com/security/SKYPE-SB-2006-002.txt
|
Vendor URL: www.skype.com/security/SKYPE-SB-2006-002.txt (Links to External Site)
|
Cause: Input validation error, State error
|
Underlying OS: UNIX (OS X)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 2 Oct 2006 16:40:28 -0400
Subject: Skype vulnerability
|
http://www.security-protocols.com/modules.php?name=News&file=article&sid=3259
CVE-2006-5084
|
|