Original URL: http://www.channelregister.co.uk/2006/10/04/skype_mac_security_update/
Skype has released an update for its Mac software following the discovery of a security vulnerability that created a means to compromise Apple PCs running the popular IP telephony application.
The security bug (http://www.skype.com/security/skype-sb-2006-002.html) stems from a format string error in the Skype URI handler. The flaw creates a potential means for hackers to create a maliciously constructed Skype URL which, if followed, might allow them to inject hostile code onto vulnerable systems.
The security bug affects Skype versions prior to 1.5.0.80. Users are advised to upgrade to this version of the software, as explained in an advisory by the firm here (http://secunia.com/advisories/22185). The bug was discovered by security researcher Tom Ferris.
In related news, Apple released a security update designed to address multiple vulnerabilities in Mac OS X (some of which have become the target of hacker exploitation) last weekend. Security notification firm Secunia has published a useful overview of these various vulnerabilities here (http://secunia.com/advisories/22187). ®
Patch Tuesday update triggered Skype outage (20 August 2007)
http://www.theregister.co.uk/2007/08/20/skype_outage_post-mortem/
Safari zero-day exploit nets $10,000 prize (20 April 2007)
http://www.channelregister.co.uk/2007/04/20/pwn-2-own_winner/
Hackers call on Skype to spread Trojan (20 December 2006)
http://www.channelregister.co.uk/2006/12/20/skype_trojan/
Skype offers Brits free yak (23 October 2006)
http://www.theregister.co.uk/2006/10/23/skype_free_calls/
VoIP services are go (18 October 2006)
http://www.theregister.co.uk/2006/10/18/voip_support_grows/
US using more mobiles than landlines (10 October 2006)
http://www.theregister.co.uk/2006/10/10/us_voip_doubles/
Vonage calls up USB key phone (5 October 2006)
http://www.reghardware.co.uk/2006/10/05/vonage_uk_v-phone/
Skype malware scam targets Turkey (10 August 2006)
http://www.channelregister.co.uk/2006/08/10/skype_spyware_scam/
'Skype clone' surfaces in China (17 July 2006)
http://www.theregister.co.uk/2006/07/17/skype_clone_controversy/
Skype bug lets 'buddies' swipe files (24 May 2006)
http://www.channelregister.co.uk/2006/05/24/skype_vuln/
Skype uses peer pressure defense to explain China text censorship (20 April 2006)
http://www.theregister.co.uk/2006/04/20/skype_china_censorship_row/
Skype explains why security evaluation omitted bug reports (7 November 2005)
http://www.channelregister.co.uk/2005/11/07/skype_vuln_analysis/
© Copyright 2008