Newsletter:

Skip Navigation LinksHome > News > Security > Skype patches Mac OS X security flaw

Skype patches Mac OS X security flaw

By Shaun Nichols
9 October 2006 10:03AM
Tags: skype | patches | mac | os | security | flaw

Vulnerability could allow for URL attacks.

Skype has release a patch for a vulnerability in its VoIP software for Mac OS X. The flaw does not affect Windows, Linux or PocketPC versions of Skype.

The vulnerability could allow an attacker to use a specially crafted Skype URL to gain access to a system and execute code. For the vulnerability to be exploited, the user would need to click on the malicious link in another application.

Skype said that the vulnerability lies within the program's URI handler, a component that decodes file locations such as URLs.

A specially formatted URL could crash the application and possibly give the attacker the ability to install and run malware on a system.

Mac OS X versions of Skype 1.5.*.79 and earlier are all affected by the vulnerability, according to the company.

Skype recommends that users download the patch from the company's website or a trusted download site.

Security firm Secunia rated the vulnerability 'highly critical', its second-highest security level. The company credits security researcher Tom Ferris with originally exposing the vulnerability.

Copyright © 2008 vnunet.com

   


Ads by Google





Product Reviews

Star Rating
The ForeScout CounterACT was the device which took the most time to install and configure.
Star Rating
The Aventail EX-1600 is a high-end SSL VPN designed for the needs of medium to large enterprises.
Star Rating
The Sophos NAC Advanced product is a well-designed offering which balances the need for ease of...
Star Rating
The Kerio WinRoute Firewall is an interesting product for this category.
Star Rating
The BiGuard S6000 extends the network to the remote user with features such as Network Extender, Transport...
ITNews NetSeminars
TopTopics
(18145) -  iphone
(5926) -  telstra
(5879) -  broadband
(4812) -  online
(4458) -  australia
(3878) -  accc
(3451) -  government
(2709) -  hack
(2702) -  computer
(1956) -  microsoft
(1794) -  information
(1696) -  smartphone
(1633) -  security
(1531) -  data
(1516) -  apple