Skype Technologies Skype for Linux GUI HTML Injection Vulnerability
BID:37603
Info
Skype Technologies Skype for Linux GUI HTML Injection Vulnerability
| Bugtraq ID: | 37603 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2010 12:00AM |
| Updated: | Jan 05 2010 12:00AM |
| Credit: | emgent and crossbower |
| Vulnerable: |
Skype Technologies Skype (Linux) 1.2 .0.17 Skype Technologies Skype (Linux) 1.1 .0.20 Skype Technologies Skype (Linux) 2.1 beta Skype Technologies Skype (Linux) 1.0.0.7 Skype Technologies Skype (Linux) 1.0.0.1 Skype Technologies Skype (Linux) 0.93.0.3 Skype Technologies Skype (Linux) 0.92.0.12 |
| Not Vulnerable: | |
Discussion
Skype Technologies Skype for Linux GUI HTML Injection Vulnerability
Skype is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected application, potentially allowing the attacker to control how the GUI is displayed to the victim; other attacks may also be possible.
Skype 2.1 beta for Linux is vulnerable; other versions may also be affected.
Skype is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected application, potentially allowing the attacker to control how the GUI is displayed to the victim; other attacks may also be possible.
Skype 2.1 beta for Linux is vulnerable; other versions may also be affected.
Exploit / POC
Skype Technologies Skype for Linux GUI HTML Injection Vulnerability
An attacker can exploit this issue by tricking a victim into viewing a malformed profile.
An attacker can exploit this issue by tricking a victim into viewing a malformed profile.
Solution / Fix
Skype Technologies Skype for Linux GUI HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Skype Technologies Skype for Linux GUI HTML Injection Vulnerability
References:
References:
- Skype Homepage (Skype Technologies)