|
|
|
Vulnerability Note VU#668193Skype VCARD handling routine contains a buffer overflowOverviewA buffer overflow in the way Skype handles imported VCARDs may allow a remote attacker to execute code on a vulnerable system.I. DescriptionSkype software provides telephone service over IP networks. Skype fails to properly validate imported VCARDs, allowing a buffer overflow to occur. The buffer overflow may stem from an input validation error in the Delphi routine SysUtils.WideFmtStr(...).For more information, please see Skype Security Bulletin SKYPE-SB/2005-002 and Delphi Bug Report 4744. Please see Skype Security Bulletin SKYPE-SB/2005-002 for a list of fixed Skype versions.
References
This vulnerability was reported by SKY-CERT. SKY-CERT credits Mark Rowe of Pentest Limited with providing information regarding this issue. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||