Skype Releases Cross Zone Vulnerability Fix

image Problem: A security bug in Skype for Windows client has been identified and fixed.

Skype uses Internet Explorer web control to render HTML content. This is used also for providing “add video to mood” and “add video to chat” functionality. The bug has been discovered in Windows Skype code which allows scripts to be run in unlocked Local Zone security context of IE and execute shell.

In order to exploit this an attacker must exploit code injection vulnerability at content provider site. Such vulnerabilities were discovered in Dailymotion website, in Metacafe Pro video submission software as well as in Skype’s own SkypeFind. All of them have been fixed at the time of issuing this bulletin.

Affected software: The following Skype clients are vulnerable to this attack:

Skype for Windows:

  • All releases including 3.5.*
  • 3.6 releases prior and including 3.6.*.244

Solution: An official fix to the issue covered by this Security Bulletin has been released.

The core vulnerability has been fixed by setting IE control security context to Internet Zone. To implement this fix, update to one of the following releases of Skype.

Skype for Windows: 3.6.*.248 or later

The preferred method for installing security updates is to download the software directly from Skype’s website, from the website of Skype’s authorized partners, or from a reliable mirror site.

Source:Skype Security Bulletin

If you like this post, please share it with someone...
  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google
  • blogmarks
  • BlogMemes
  • Furl
  • Live
  • NewsVine
  • SphereIt
  • Spurl
  • StumbleUpon
  • Technorati

Get Mobility Site via Email

You can also participate in other conversation in our active forums with 200,000 other Members. It only takes 2 minutes to sign up one time for free in the forums. Thanks for reading.

Leave a Reply

You can use these XHTML tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>

You Should Also Check Out These Posts:

More Active Posts:

About Mobilitysite

Mobilitysite.com is a site covering Mobility News, Reviews, and Discussion. Our coverage focuses on Windows Mobile Phones and PDAs, but extends on past that as well. Tablet PC, UMPC, and Personal Media Players like the Zune and iPod are loosely covered as well. To learn more about Mobilitysite and/or Aximsite, read here. Also take time to register in our forums too. There is a wealth of information to be found inside and registering yourself in the forums also registers you with the blog portion of the site.

Mobilitysite - Aximsite - Hard Reset Guide - AT&T Tilt Site

Contact Us - About Us - Privacy Policy - Advertise - News Archives - Forum Archives - Donate - Top