Advertisement
Promo

Office applications Toolkit

Skype fixes critical security flaw

Peter Judge ZDNet.co.uk

Published: 07 Dec 2007 17:47 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Skype has fixed a critical security hole in the latest version of its Windows VoIP software, which could have allowed specially crafted websites to load and run malicious code on victims' PCs.

The URI handler skype4com, which the Skype software creates to handle web addresses, can fail when handling short strings, producing a memory violation that allows code to be written to memory.

"It is clear that Skype has once again closed critical holes furtively without informing users at all," said security website Heise Security.

Users of older versions of the software should make sure they are running the latest version of Skype — version 3.6.

Security research firm Secunia, which rated the flaw as critical, offers a Software Inspector that should determine if a PC is vulnerable.

Meanwhile, Skype has been criticised by users for allegedly not responding to bug reports.

Applications development professional and ZDNet.co.uk member Jamie Watson reported in his blog on Thursday comments from a Skype forum that Skype was producing 10,000 page faults per second on a user's computer.

Quoting from the forum, Watson said that for nearly two months Skype took the stance that the software was designed to produce that volume of faults. Finally, the VoIP company appeared to admit that the error was created by a thread, which Skype programmers put in for debugging and forgot to take out.

Skype could offer no response to Watson's comments at the time of writing.

The VoIP company has fallen out of favour with some of its other customers over the past few weeks. In November it withdrew a swathe of its users' telephone numbers, starting with the prized prefix 0207, after it fell out with one of its suppliers.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
17 out of 19 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Discussions

1000215420 1000215420

NHS spending question

Wednesday 25 November 2009, 2:31 AM

2 comments
lezlow lezlow

scots mate

Wednesday 25 November 2009, 12:46 AM

4 comments
lezlow lezlow

disconnect internet

Wednesday 25 November 2009, 12:34 AM

4 comments
CA CA

Uhm..

Tuesday 24 November 2009, 11:01 PM

8 comments

Vista Upgrade Blog

This Crap Site

How utterly stupid - I am ranked #40 in the top 100 - as a member of this site..... I mean HOW utterly stupid.... I have done sweet FA, I have only rejoined this site after a 3 or... More

2 comments

Microsoft Security Update: November Pa...

Apologies for this late update to our core Patch Tuesday update. Here is a summary of the update .... The November Patch Tuesday update from Microsoft follows the largest patch and... More

Post a comment

Windows 7 pricing all over the shop..a...

I really think Microsoft have made a mess of Windows 7 pricing. They got the product right, yet there initial pricing of at around £44.95 for the full version of Windows 7 Home Premium... More

7 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters