Skype bug lets 'buddies' swipe files
A Windows special
Posted in Software & Security, 24th May 2006 17:07 GMT
Free whitepaper – Managing desktop software for fun and profit
Skype has warned of a flaw in its popular VoIP client software that creates a means for hackers to swipe files from their "buddies". The flaw can be exploited via a malicious constructed Skype URL which initiates the transfer of a single named file to another Skype user.
The security bug stems from an error within the parsing of the parameters passed by the URL handler. This flaw creates a means for hackers to inject commands within a maliciously crafted Skype URL that initiates transfer of a file from one Skype user without requiring the sender to explicitly consent to the action. However, this only works if a trust relationship already exists between the two parties, drastically restricting the scope for mischief.
The bug, which is not easy to exploit, applies only to Skype for Windows and not other versions of the software. Users are advised to update to Skype 2.5, release 2.5.*.79 or Skype 2.0, release 2.0.*.105 or later as explained in an advisory here. ®
Free whitepaper – Managing desktop software for fun and profit
Analyst Keynote: The Register Agile Data Center Summit
Dell PowerEdge R710 solution with VMware ESX vs. Dell PowerEdge 2850 solution
Seven ways to lower storage costs

Sign up, sign up for The Register IT security newsletter
Microsoft's Windows 7 price gamble - and why it's flawed
Managing Desktop Software for fun and profit
Intel's flash new SSDs hit by bugs