ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

VoIP Toolkit

Skype flaw puts users at risk

Joris Evers CNET News.com

Published: 26 Oct 2005 09:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Skype Technologies updated its popular Skype Internet telephony software on Tuesday to fix a pair of security bugs. The most serious flaw could allow an attacker to commandeer a user's PC.

That flaw, which is similar to a bug Skype fixed last year, affects only Skype for Windows. An attacker could exploit the flaw by crafting a special link and enticing a user to click on it. The flaw could also be exploited when importing user information from a malformed electronic business card, or VCARD, Skype said in an advisory.

A second vulnerability affects Skype on all platforms, but could only be exploited in a denial-of-service attack, Skype said in another advisory. Skype clients are available for Windows; Mac OS X v10.3 (Panther) or later; Linux; and Windows Mobile 2003 for Pocket PC, Skype said.

Security information aggregator Secunia rates the flaws "highly critical" in its advisory, one notch below its highest rating. The company uses the rating for remotely exploitable vulnerabilities that can lead to a system becoming compromised.

Skype was acquired by online auctioneer eBay in September. The client software has been downloaded more than 186 million times since its launch in August 2003 and 61 million people are registered to use the service, according to Skype's Web site. More than 3 million people use Skype simultaneously at any given time, the company said.

Skype on Tuesday released updated versions of its software for Windows, Mac OS X and Linux that do not contain the bugs. A fixed version of the application for Pocket PCs is forthcoming, according to Skype's security advisory.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
86 out of 187 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

FIX CONNECTIVITY - LONDON - PERMANENT

FIX Support Engineer with strong client facing skills required for a leading boutique financial software organisation. An in-depth knowledge of FIX ...

Hardware Break/Fix Engineer

ESG provides hardware support in the form of COTS Integration and Installation, and Break/Fix services to EDS Defence Projects based mainly in Hook. ...

JUNIOR JAVA DEVELOPER

To Apply Please email us an updated CV and a cover letter explaining why you feel you are suited to the role by pressing the apply button below. ...

Featured White Papers

See All White Papers