|
Family: Windows --> Category: infos
Skype Networking Routine Heap Overflow Vulnerability (SMB check) Vulnerability Scan
Vulnerability Scan Summary Checks for Skype Heap overflow for Windows
Detailed Explanation for this Vulnerability Test
Synopsis :
Arbitrary code can be executed on the remote host.
Description :
The remote host is running Skype, a peer-to-peer voice over IP
software.
The remote version of this software is vulnerable to a Heap overflow
in the handling of its data structures. A possible hacker can exploit this
flaw by sending a specially crafted network packet to UDP or TCP ports
Skype is listenning on.
A successful exploitation of this flaw will result in code execution
on the remote host.
See also :
http://www.skype.com/security/skype-sb-2005-03.html
Solution :
Upgrade to skype version 1.4.0.84 or later.
Threat Level:
High / CVSS Base Score : 8
(AV:R/AC:H/Au:NR/C:C/A:C/I:C/B:A)
Click HERE for more information and discussions on this network vulnerability scan.
|