Skype Technologies skype4com URI Handler Remote Heap Corruption Vulnerability
BID:26748
Info
Skype Technologies skype4com URI Handler Remote Heap Corruption Vulnerability
| Bugtraq ID: | 26748 |
| Class: | Design Error |
| CVE: |
CVE-2007-5989 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2007 12:00AM |
| Updated: | Dec 07 2007 05:32PM |
| Credit: | An anonymous researcher is credited for the discovery of this issue. |
| Vulnerable: |
Skype Technologies Skype 2.5 .79 Skype Technologies Skype 2.5 .78 Skype Technologies Skype 2.0 .105 Skype Technologies Skype 2.0 .104 Skype Technologies Skype 1.5 80 Skype Technologies Skype 1.5 .79 Skype Technologies Skype 1.4 .0.83 Skype Technologies Skype 1.1 .0.0 Skype Technologies Skype 1.0 .0.97 Skype Technologies Skype 1.0 .0.94 Skype Technologies Skype 1.0 .0.9 Skype Technologies Skype 1.0 .0.29 Skype Technologies Skype 1.0 .0.18 Skype Technologies Skype 1.0 .0.100 Skype Technologies Skype 1.0 .0.10 Skype Technologies Skype 2.5 Skype Technologies Skype 2.0 Skype Technologies Skype 0.98.0.04 Skype Technologies Skype |
| Not Vulnerable: |
Skype Technologies Skype 3.6 .216 |
Discussion
Skype Technologies skype4com URI Handler Remote Heap Corruption Vulnerability
Skype is prone to a remote heap-based memory-corruption vulnerability because of a flaw in the application's URI handler.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application, facilitating the compromise of affected computers.
Versions prior to Skype 3.6.0.216 for Windows are affected. It is currently unknown if other platforms are affected.
Skype is prone to a remote heap-based memory-corruption vulnerability because of a flaw in the application's URI handler.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application, facilitating the compromise of affected computers.
Versions prior to Skype 3.6.0.216 for Windows are affected. It is currently unknown if other platforms are affected.
Exploit / POC
Skype Technologies skype4com URI Handler Remote Heap Corruption Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Skype Technologies skype4com URI Handler Remote Heap Corruption Vulnerability
Solution:
The vendor has released Skype 3.6.0.216 for Windows to address this issue. It is currently unknown if other platforms are affected or if fixes are available. Users should contact the vendor for more information.
Solution:
The vendor has released Skype 3.6.0.216 for Windows to address this issue. It is currently unknown if other platforms are affected or if fixes are available. Users should contact the vendor for more information.
References
Skype Technologies skype4com URI Handler Remote Heap Corruption Vulnerability
References:
References:
- Skype Homepage (Skype Technologies)
- Skype Windows Download Page (Skype Technologies)
- ZDI-07-070: Skype skype4com URI Handler Remote Heap Corruption Vulnerability ([email protected])