Newsletter:

Skip Navigation LinksHome > News > Security > Skype patches Mac OS X security flaw

Skype patches Mac OS X security flaw

By Shaun Nichols
9 October 2006 10:03AM
Tags: skype | patches | mac | os | security | flaw

Vulnerability could allow for URL attacks.

Skype has release a patch for a vulnerability in its VoIP software for Mac OS X. The flaw does not affect Windows, Linux or PocketPC versions of Skype.

The vulnerability could allow an attacker to use a specially crafted Skype URL to gain access to a system and execute code. For the vulnerability to be exploited, the user would need to click on the malicious link in another application.

Skype said that the vulnerability lies within the program's URI handler, a component that decodes file locations such as URLs.

A specially formatted URL could crash the application and possibly give the attacker the ability to install and run malware on a system.

Mac OS X versions of Skype 1.5.*.79 and earlier are all affected by the vulnerability, according to the company.

Skype recommends that users download the patch from the company's website or a trusted download site.

Security firm Secunia rated the vulnerability 'highly critical', its second-highest security level. The company credits security researcher Tom Ferris with originally exposing the vulnerability.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 






Product Reviews

Star Rating
CynapsPro Suite 2008 is another tiered protection mechanism.
Star Rating
Safend Protector is an offering that is less of a suite of products and more of a unified application.
Star Rating
Blink is an endpoint security product that functions as a network protector.
Star Rating
EndPointSecurity installs a small footprint agent on the machine.
Star Rating
GuardianEdge Device Control is a component of the more robust GuardianEdge Data Protection Platform.
Product Reviews now available on iTnews.com.au

TopTopics
(3697) -  microsoft
(1980) -  telstra
(1820) -  broadband
(1579) -  network
(1448) -  windows
(1376) -  mobile
(1297) -  security
(1177) -  blackberry
(1047) -  apple
(1020) -  data
(821) -  nbn
(781) -  storm
(759) -  television
(732) -  linux
(724) -  internet