Could allow buffer overflow of Windows-based machines...
By Robert Lemos
Published: 16 November 2004 08:13 GMT
Peer-to-peer phone company Skype has updated its internet telephony software, patching a critical flaw in its client for Microsoft Windows-based systems. The patch is available from Skype's website.
Security information provider Secunia said on Monday the vulnerability could allow attackers to take control of a Skype user's PC after the victim clicks on a specially created URL. By including a long string of characters in the link, the attacker could trigger a memory error known as a buffer overflow that could then be exploited to run a program.
"Successful exploitation may allow execution of arbitrary code," Secunia said. It has ranked the flaw as "highly critical" - its second-highest rating.
Kelly Larabee, a spokeswoman for Skype, said the company acknowledged the security hole in its release notes for the update. "We became aware of a security threat late last week and moved to correct it. We encourage users to download the latest version."
Skype's software enables people to use the internet to place voice calls. Calls to other internet phone users are free, while calls to traditional phones and mobile phones are charged a per-minute fee. More than 34 million people have downloaded the software, and as many as one million people have used the service simultaneously, according to a posting on Skype's website.
Skype's voice over Internet Protocol (VoIP) client runs on Windows XP, Mac OS X, Linux and Microsoft PocketPC.
Secunia also recommended that Skype users update to the latest version of the VoIP software.
Robert Lemos writes for CNET News.com.
Back to VoIP Special Report
Skype rings changes with standalone VoIP phone
No need for wi-fi or a PC...
Skype goes Mac
Now graphic designers can beta path to Skype's door...
Report slams US VoIP-tapping policy
It'll give hackers a helping hand, say security specialists
Skype sued for patent violation
Net2Phone cries foul...
Vonage shareholders sue over IPO
'Our cash was their exit strategy... '
Stories from around the web...
Skype dreams for developers CNET News.com
Enterprise VoIP: To adopt or not to adopt? Telephony Online
How scalable is your VoIP solution? TechRepublic - free subscription required
Despite the buzz, VOIP still has hurdles to overcome GCN.com
Make your voice heard
silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.
Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.
Extras include complementary passes to silicon.com events and survey prizes such as iPods. Plus, there are the obvious networking opportunities with your fellow panellists.
For more about the Research Panel and how to join, click here
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page