Skype Technologies Skype Client for Mac Chat Feature Remote Denial of Service Vulnerability
BID:41040
Info
Skype Technologies Skype Client for Mac Chat Feature Remote Denial of Service Vulnerability
| Bugtraq ID: | 41040 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2010 12:00AM |
| Updated: | Jun 22 2010 12:00AM |
| Credit: | Marc Ruef at scip AG |
| Vulnerable: |
Skype Technologies Skype 1.3 .275 Skype Technologies Skype 2.8 |
| Not Vulnerable: | |
Discussion
Skype Technologies Skype Client for Mac Chat Feature Remote Denial of Service Vulnerability
Skype is prone to a remote denial-of-service vulnerability because it fails to properly sanitize user-supplied input in the embedded chat feature.
Successfully exploiting this issue allows remote attackers to deny service to legitimate users.
Skype 1.3.0.275 for Apple iPhone and 2.8 for Mac OS X are vulnerable; other versions may also be affected.
Skype is prone to a remote denial-of-service vulnerability because it fails to properly sanitize user-supplied input in the embedded chat feature.
Successfully exploiting this issue allows remote attackers to deny service to legitimate users.
Skype 1.3.0.275 for Apple iPhone and 2.8 for Mac OS X are vulnerable; other versions may also be affected.
Exploit / POC
Skype Technologies Skype Client for Mac Chat Feature Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Skype Technologies Skype Client for Mac Chat Feature Remote Denial of Service Vulnerability
Solution:
The vendor indicates that this issue will be patched in the next major release.
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
The vendor indicates that this issue will be patched in the next major release.
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Skype Technologies Skype Client for Mac Chat Feature Remote Denial of Service Vulnerability
References:
References:
- Skype Homepage (Skype Technologies)
- [scip_Advisory 4142] Skype Client for Mac Chat Unicode Denial of Service (Marc Ruef
)