Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Windows --> Category: infos

Skype Networking Routine Heap Overflow Vulnerability (SMB check) Vulnerability Scan


Vulnerability Scan Summary
Checks for Skype Heap overflow for Windows

Detailed Explanation for this Vulnerability Test

Synopsis :

Arbitrary code can be executed on the remote host.

Description :

The remote host is running Skype, a peer-to-peer voice over IP
software.

The remote version of this software is vulnerable to a Heap overflow
in the handling of its data structures. A possible hacker can exploit this
flaw by sending a specially crafted network packet to UDP or TCP ports
Skype is listenning on.

A successful exploitation of this flaw will result in code execution
on the remote host.

See also :

http://www.skype.com/security/skype-sb-2005-03.html

Solution :

Upgrade to skype version 1.4.0.84 or later.

Threat Level:

High / CVSS Base Score : 8
(AV:R/AC:H/Au:NR/C:C/A:C/I:C/B:A)

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.