Skype Patches Security VulnerabilityBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard Network Security Scanner - Dld 30-day trial! del.icio.us  digg  Furl  NewsVine  Spurl  Blinklist  Ma.gnolia  Reddit  Tailrank  YahooMyWeb 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Downloads
RSS / Atom Feeds
Windows Security : Skype Patches Security Vulnerability
Posted by Max on 2008/6/9 15:01:33 (384 reads)

Skype released a security bulletin describing a recently found vulnerability :Skype File URI Security Bypass Code Execution Vulnerability. Affected are all Skype Windows clients prior to and including
3.8.*.115, with the vulnerability already fixed in versions 3.8.0.139.

1. Problem description and brief discussion
Remote exploitation of a security policy bypass in Windows Skype versions could allow an attacker to execute arbitrary code.

URI handler in Skype performs checks upon the URL to verify that the link does not contain certain file extensions related to executable file formats. If the link is found to contain a blacklisted executable file extension a security warning dialog is shown to the user. This check is flawed in two ways. The check is performed using the case sensitive comparison.

The second flaw in this check is that the blacklist fails to mention all potential executable file formats. This allows an attacker to bypass this security policy and execute arbitrary code if a victim clicks an attacker supplied URL.

2. Impact and affected software
Exploitation of this issue allows an attacker to execute arbitrary code on the targeted victim's machine. An attacker would need to construct a malicious file: URI and send it to the intended victim. Upon clicking the link execution of arbitrary code on the victim's machine will be possible.

Affected software
The following Skype clients are vulnerable to this attack:

Skype for Windows:
All releases prior to and including 3.8.*.115

3. Solution or work-around
Skype has fixed the vulnerability in version 3.8.0.139

4. Special instructions and notes
None.

5. Software download location
The preferred method for installing security updates is to download the software directly from Skype's website, from the website of Skype's authorized partners, or from a reliable mirror site. Skype may also be safely downloaded from other locations, but in this case it is particularly important that you verify the authenticity of the download.

We recommend that once you download any Skype software that you verify its integrity by the methods listed in Section 6 of this Bulletin.

x86 platform, Microsoft Windows 2000 or Microsoft Windows XP: http://www.skype.com/download/skype/windows/

x86 platform, Linux: http://www.skype.com/download/skype/linux/

PPC and x86 platforms, Mac OS X v10.3.9 or later: http://www.skype.com/download/skype/macosx/

Pocket PC platform, Microsoft Windows Mobile 2003: http://www.skype.com/download/skype/pocketpc/

6. Authenticity verification

- Bulletin authenticity verification:
Skype security bulletins are published on Skype's web site and via mailing lists. The authenticity and integrity of a Skype security bulletins may be determined by inspecting the crypto- graphic signature that is attached to each bulletin. All Skype security bulletins are published with a valid digital signature produced by PGP.

- Software authenticity verification:
Both the Skype installer program and the Skype program that is installed by the installer are digitally signed.

For Skype software built for Microsoft Windows and Mac OSX operating environments, the digital certificate used by Skype to sign software packages is signed by "VeriSign Class 3 Code Signing 2004 CA".

For Skype software built for Linux platforms, all packages are signed by PGP key ID 0xD66B746E, the public component of which may be downloaded from http://www.skype.com/download/skype/linux/.

- For general information about Skype security, please visit the Skype Security Resource Center at http://www.skype.com/security/.




Other articles
2008/8/21 15:52:01 - BitRoll and Torrent101 Used to Distribute the Lop Adware
2008/8/20 15:06:33 - FRAUDFacts Helps You Fight Identity Theft and Fraud for Life
2008/8/13 16:42:03 - 10 Million Zombies Are Spreading Spam and Malware Every Day
2008/8/11 9:03:35 - Nearly $8.5 Billion Lost by US Consumers because of Online Threats
2008/8/8 6:35:36 - EDS' Eight Tips for Consumers to Protect Themselves from Identity Theft

The comments are owned by the poster. We aren't responsible for their content.