Skype Update Patches Security Print E-mail
Written by Adam Gosling   
Wednesday, 26 October 2005
The latest update from Skype is to address critical security flaws which the company divulged earlier this week.

The flaws are believed to be two of the three highlighted by security researcher Secunia.

The flaws could allow attackers to take over a Skype user's system, Skype said in an advisory published yesterday –here and here.

One flaw is easily exploited by social engineering techniques. A Skype user would need to click on a specially-crafted URL. The other would require a Skype user to import a malicious vCard.

Secunia rated the flaws as highly critical and added another to Skype’s list which affects Mac and Linux users as well. Secunia says a boundary error exists in the handling of certain unspecified Skype client network traffic.

This can be exploited to cause a heap-based buffer overflow. However, this exploit seems limited to the ability to crash the Skype client.

The Secunia advisory is here.

Related news items
Newer news items
Older news items
 
mobilised

Carrier News

Ructions At Engin Signal Changing Strategy
With the 30 per cent acquisition of pure play VoIP service provider, Engin, by the Seven Network, it was only a matter of time before major upheaval filtered its way to the broadband telephony provider's staff.
Older news items
 

Industry News

Vendor News

Aspect Maps Out UC Product Plans
Contact Centre software specialists, Aspect Software, has embarked on a corporate strategy to educate the market on the part the contact centre plays in an organisation's overall unified communications strategy.
Older news items
 

VoIP Solutions

Product News

WA Dept Education Goes IP With Panasonic
The West Australian Department of Education and Training has chosen Panasonic for the upgrade of all future school telephony systems to IP-capable solutions.
Older news items