Skype Technologies Skype NSRunAlertPanel Remote Format String Vulnerability
BID:20218
Info
Skype Technologies Skype NSRunAlertPanel Remote Format String Vulnerability
| Bugtraq ID: | 20218 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5084 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2006 12:00AM |
| Updated: | Oct 05 2006 06:30PM |
| Credit: | Tom Ferris discovered this issue. |
| Vulnerable: |
Skype Technologies Skype 1.5 .79 |
| Not Vulnerable: |
Skype Technologies Skype 1.5 80 |
Discussion
Skype Technologies Skype NSRunAlertPanel Remote Format String Vulnerability
Skype is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied input before using it in the format-specification argument of a formatted-printing function.
Exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application, potentially facilitating the remote compromise of affected computers.
Skype 1.5.0.79 and prior versions for Apple Mac OS X are vulnerable to this issue.
Skype is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied input before using it in the format-specification argument of a formatted-printing function.
Exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application, potentially facilitating the remote compromise of affected computers.
Skype 1.5.0.79 and prior versions for Apple Mac OS X are vulnerable to this issue.
Exploit / POC
Skype Technologies Skype NSRunAlertPanel Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The following proof of concept is available:
IFRAME SRC=skype:%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The following proof of concept is available:
IFRAME SRC=skype:%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n
Solution / Fix
Skype Technologies Skype NSRunAlertPanel Remote Format String Vulnerability
Solution:
The vendor has released an advisory and fixes to address this issue. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes to address this issue. Please see the references for more information.
References
Skype Technologies Skype NSRunAlertPanel Remote Format String Vulnerability
References:
References:
- Fun with Skype on OSX... (Tom Ferris)
- Skype 'NSRunAlertPanel' URI Argument Handler Format String (Security-Protocols)
- Skype 1.5.0.79 Format String Vulnerability (Null Pointer) (Tom Ferris)
- Skype Homepage (Skype Technologies)
- SKYPE-SB/2006-002: Improper handling of URI arguments (Skype)