Skype for Mac URI Argument Handling Remote Command Execution Vulnerability
Technical Description



A vulnerability has been identified in Skype, which could be exploitedby remote attackers to take complete control of an affected system.This flaw is due to a format string error when processing malformed URIarguments, which could be exploited by attackers to crash a vulnerableapplication or execute arbitrary commands by convincing a user tofollow a malformed Skype URL.



Affected Products



Skype for Mac versions prior to 1.5.0.80



Solution



Upgrade to version 1.5.0.80 :

http://www.skype.com/download/



References



http://www.skype.com/security/skype-sb-2006-002.html
더보기

댓글,