Newsletters

Select newsletters below and click the button to sign up!

Boston News NY News
DC News Internet Daily
SiliconValley News
InternetNews Business Report




Become a Marketplace Partner



Partner With Us















Internetnews Bloggers

Recent Entries

Archives

April 2009
Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    

Monthly Archives

Search The Blog

Netstat -vat by Sean Michael Kerner (bio)

A command line view of IT



Skype at risk from security vulnerability

skype.jpg
Skype users may be a risk from a moderately critical code execution vulnerability that could potentially allow an attacker to execute arbitrary code.

The vulnerability stems from how Skype handles URIs.According to an advisory from VeriSign's iDefense security research team:
The "file:" URI handler in Skype performs checks upon the URL to verify that the link does not contain certain file extensions related to executable file formats... Due to improper logic when performing these checks, it is possible to bypass the security warning and execute the program. 
Skype in its own advisory on the issue elaborates on how the vulnerability could be triggered by an attacker.
An attacker would need to construct a malicious file: URI and send it to the intended victim. Upon clicking the link execution of arbitrary code on the victim's machine will be possible.
All Skype for Windows releases releases prior to and including 3.8.*.115 are at risk. The vulnerability has been fixed in the newly released version 3.8.0.139.

If you're a Skype user don't rely on getting an update notification before you update. In my case. I was running 3.8.0.115, I hit the 'check for updates' button and got a window stating that I had the most recent version of Skype (which isn't actually the case). In my limited experience with this issue, you actually need to physcially visit the Skype download page and download the latest version to make certain you're not at risk from this URI vulnerability.

| Comments (1) | TrackBacks (0) | Share

0 TrackBacks

Listed below are links to blogs that reference this entry: Skype at risk from security vulnerability.

TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/3674

1 Comments

J.A. Watson said:

You are correct about the Skype "check for updates" function not working. In fact, one of the "experts" on the Skype Community (formerly User Forums) said "I have never seen that work once in all the years that I have been using Skype".

If you read the Skype Community, you are likely to be shocked at how often the "experts" tell users who are having the typical problems with Skype audio and video to go back to a previous version of Skype, WITHOUT warning them that the older versions have these kinds of security problems.

Leave a comment