Original URL: http://www.channelregister.co.uk/2006/05/24/skype_vuln/
Skype has warned of a flaw in its popular VoIP client software that creates a means for hackers to swipe files from their "buddies". The flaw can be exploited via a malicious constructed Skype URL which initiates the transfer of a single named file to another Skype user.
The security bug stems from an error within the parsing of the parameters passed by the URL handler. This flaw creates a means for hackers to inject commands within a maliciously crafted Skype URL that initiates transfer of a file from one Skype user without requiring the sender to explicitly consent to the action. However, this only works if a trust relationship already exists between the two parties, drastically restricting the scope for mischief.
The bug, which is not easy to exploit, applies only to Skype for Windows and not other versions of the software. Users are advised to update to Skype 2.5, release 2.5.*.79 or Skype 2.0, release 2.0.*.105 or later as explained in an advisory here (http://www.skype.com/security/skype-sb-2006-001.html). ®
Hackers call on Skype to spread Trojan (20 December 2006)
http://www.channelregister.co.uk/2006/12/20/skype_trojan/
Skype patches Mac OS X flaw (4 October 2006)
http://www.channelregister.co.uk/2006/10/04/skype_mac_security_update/
Fugitive CEO tracked down to Sri Lanka after Skype call (25 August 2006)
http://www.theregister.co.uk/2006/08/25/fugitive_ceo_cuffed/
'Skype clone' surfaces in China (17 July 2006)
http://www.theregister.co.uk/2006/07/17/skype_clone_controversy/
Intel pitches VoIP card at office-PC users (7 June 2006)
http://www.reghardware.co.uk/2006/06/07/intel_ships_voip_pci_card/
VoIP firm backs 'virtual' yacht race (6 June 2006)
http://www.theregister.co.uk/2006/06/06/voip_art/
PGP creator offers VoIP crypto to Windows users (23 May 2006)
http://www.channelregister.co.uk/2006/05/23/zfone/
Security pros give VoIP the brush-off (27 April 2006)
http://www.channelregister.co.uk/2006/04/27/infosec_voip_debate/
Skype uses peer pressure defense to explain China text censorship (20 April 2006)
http://www.theregister.co.uk/2006/04/20/skype_china_censorship_row/
Botnet control fears over IP telephony (26 January 2006)
http://www.channelregister.co.uk/2006/01/26/voip_botnet_control_fears/
Skype explains why security evaluation omitted bug reports (7 November 2005)
http://www.channelregister.co.uk/2005/11/07/skype_vuln_analysis/
Scramble to fix Skype security bug (25 October 2005)
http://www.channelregister.co.uk/2005/10/25/skype_vuln/
© Copyright 2008