Security Update For Skype

Published: June 7th, 2008 | Category: Security Vulnerabilities

Skype recently released an update to their Windows client to fix a major security issue. The Skype advisory is SB/2008-003: Skype File URI Security Bypass Code Execution Vulnerability. The latest Skype for Windows client is now 3.8.0.139.

There are some more details of the vulnerability on the iDefense Labs advisory page.

II. DESCRIPTION

Remote exploitation of a security policy bypass in Skype could allow an attacker to execute arbitrary code in the context of the user.

The "file:" URI handler in Skype performs checks upon the URL to verify that the link does not contain certain file extensions related to executable file formats. If the link is found to contain a blacklisted file extension, a security warning dialog is shown to the user. The following file extensions are checked and considered dangerous by Skype; .ade, .adp, .asd, .bas, .bat, .cab, .chm, .cmd, .com, .cpl, .crt, .dll, .eml, .exe, .hlp, .hta, .inf, .ins, .isp, .js.

Due to improper logic when performing these checks, it is possible to bypass the security warning and execute the program. First of all, checking is performed using a case sensitive comparison. The second flaw in this check is that the blacklist fails to mention all potential executable file formats. By using at least one upper case character, or using an executable file type that is not covered in the list, an attacker can bypass the security warning.

Upgrade now to the latest Skype for Windows.

  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • Reddit
  • StumbleUpon
  • TailRank
  • Technorati
  • TwitThis

Tags:

RSS feed | Trackback URI

Comments »

No comments yet.

Name (required)
E-mail (required - never shown publicly)
URI
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.

Trackback responses to this post

Infosec Events. Copyright 2010. All Rights Reserved.
Home - Calendar - Communities - Training - Archives - Contact