Security hole in Skype can inject files on your PC

The improper handling of URI arguments can initiates the transfer of a single named file from one to another Skype user.

An attacker can construct a malformed URL that can initiate the transfer of a single named file from one Skype user to another. Successful exploitation requires that the user follows a malicious Skype URL and that the recipient has previously authorised the sender.

Affected versions:

Skype for Windows:
All releases prior to and including 2.0.*.104
Release 2.5.*.0 to and including 2.5.*.78

More information can be found here.

The official workaround is available here.

Digg this story | Bookmark this post on del.icio.us

No Comments so far
Leave a comment



Leave a comment
Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>

(required)

(required)