|
|
|
Vulnerability Note VU#930345Skype URI handling routine contains a buffer overflowOverviewA buffer overflow in Skype may allow a remote attacker to execute code on a vulnerable system.I. DescriptionSkype software provides telephone service over IP networks. There is a buffer overflow in the routines that handle Skype-specific URIs (callto:// or skype://). The buffer overflow may stem from an input validation error in the Delphi routine SysUtils.WideFmtStr(...).For more information, please see Skype Security Bulletin SKYPE-SB/2005-002 and Delphi Bug Report 4744.
Please see Skype Security Bulletin SKYPE-SB/2005-002 for a list of fixed Skype versions.
References
This vulnerability was reported by SKY-CERT. SKY-CERT credits Mark Rowe of Pentest Limited with providing information regarding this issue. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||