Skype Web Content Zone Remote Code Execution Vulnerability
BID:27338
Info
Skype Web Content Zone Remote Code Execution Vulnerability
| Bugtraq ID: | 27338 |
| Class: | Design Error |
| CVE: |
CVE-2007-5989 CVE-2008-0582 CVE-2008-0583 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 17 2008 12:00AM |
| Updated: | Feb 13 2008 10:16PM |
| Credit: | Aviv are credited with the discovery of this issue. Miroslav Luinskij is credited with the discovery of how to leverage the issue via DailyMotion. |
| Vulnerable: |
Skype Technologies Skype 3.6 .244 Skype Technologies Skype 3.6 .216 Skype Technologies Skype 3.6 Skype Technologies Skype 3.5 |
| Not Vulnerable: | |
Discussion
Skype Web Content Zone Remote Code Execution Vulnerability
Skype is prone to a vulnerability that allows arbitrary code to run. The issue occurs because the application uses Windows 'Web content Zones' in an insecure manner.
Attackers can leverage the issue by enticing an unsuspecting user to use a Skype dialog on a malicious web object. Successful exploits will allow arbitrary code to run in the context of the user running the application.
Skype 3.5 and 3.6 series are vulnerable.
Skype is prone to a vulnerability that allows arbitrary code to run. The issue occurs because the application uses Windows 'Web content Zones' in an insecure manner.
Attackers can leverage the issue by enticing an unsuspecting user to use a Skype dialog on a malicious web object. Successful exploits will allow arbitrary code to run in the context of the user running the application.
Skype 3.5 and 3.6 series are vulnerable.
Exploit / POC
Skype Web Content Zone Remote Code Execution Vulnerability
The following video demonstrates an example exploit. The DailyMotion website service allows users to upload videos for public viewing. Due to an input-validation issue affecting the website, attackers can inject arbitrary code in the 'Title' field when uploading videos. When a Skype user accesses DailyMotion via Skype's 'Add video to chat' page and the malicious title is displayed, the attacker's code executes.
http://www.youtube.com/watch?v=FcuQrLZ4AU0
Metacafe videos are also reported to be an attack vector for this issue. Proof-of-concept code is reported to exist, but not publicly available.
The following video demonstrates an example exploit. The DailyMotion website service allows users to upload videos for public viewing. Due to an input-validation issue affecting the website, attackers can inject arbitrary code in the 'Title' field when uploading videos. When a Skype user accesses DailyMotion via Skype's 'Add video to chat' page and the malicious title is displayed, the attacker's code executes.
http://www.youtube.com/watch?v=FcuQrLZ4AU0
Metacafe videos are also reported to be an attack vector for this issue. Proof-of-concept code is reported to exist, but not publicly available.
Solution / Fix
Skype Web Content Zone Remote Code Execution Vulnerability
Solution:
The vendor released a temporary fix to address this issue. The fix disables the ability to add videos from DailyMotion. The vendor states that an official fix is forthcoming. Please see the references for more information.
UPDATE (January 22, 2008): The vendor has disabled the use of video in Skype until an update is available.
UPDATE (February 6, 2008): Skype has fixed these vulnerabilities in the latest version. Please see the referenced advisories for information about obtaining fixes.
Solution:
The vendor released a temporary fix to address this issue. The fix disables the ability to add videos from DailyMotion. The vendor states that an official fix is forthcoming. Please see the references for more information.
UPDATE (January 22, 2008): The vendor has disabled the use of video in Skype until an update is available.
UPDATE (February 6, 2008): Skype has fixed these vulnerabilities in the latest version. Please see the referenced advisories for information about obtaining fixes.
References
Skype Web Content Zone Remote Code Execution Vulnerability
References:
References:
- No more videos for you. Come back when patch available! (Aviv Raff)
- Skype for Windows Download Page (Skype Technologies)
- Skype Homepage (Skype Technologies)
- SKYPE-SB/2008-002: Skypefind Cross Zone Scripting Vulnerability (Skype)
- UPDATE 1 SKYPE-SB/2008-001: Skype Cross Zone Scripting Vulnerability (Skype)
- UPDATE 2 SKYPE-SB/2008-001: Skype Cross Zone Scripting Vulnerability (Skype)
- Attackers can SkypeFind you ("avivra"
) - Skype cross-zone scripting vulnerability (Aviv Raff On.NET)
- SKYPE-SB/2008-001: Skype Cross Zone Scripting Vulnerability (Skype)
- VU#248184 Skype does not properly filter input from external websites (US-CERT)
- Vulnerability Note VU#794236 SkypeFind fails to properly sanitize user-supplied (US-CERT)