Flaws could mean PC hijackings...
By Joris Evers
Published: 26 October 2005 08:55 GMT
Skype updated its popular internet telephony software on Tuesday to fix a pair of security bugs. The most serious flaw could allow an attacker to commandeer a user's PC.
That flaw, which is similar to a bug Skype fixed last year, affects only Skype for Windows. An attacker could exploit the flaw by crafting a special link and enticing a user to click on it. The flaw could also be exploited when importing user information from a malformed electronic business card, or VCARD, Skype said in an advisory.
A second vulnerability affects Skype on all platforms but could only be exploited in a denial of service attack, Skype said in another advisory. Skype clients are available for Windows; Mac OS X v10.3 (Panther) or later; Linux; and Windows Mobile 2003 for Pocket PC, Skype said.
Security information aggregator Secunia rates the flaws "highly critical", one notch below its highest rating. The company uses the rating for remotely exploitable vulnerabilities that can lead to a system becoming compromised.
Skype was acquired by online auctioneer eBay in September. The client software has been downloaded more than 186 million times since its launch in August 2003 and 61 million people are registered to use the service, according to Skype's website. More than three million people use Skype simultaneously at any given time, the company said.
Skype on Tuesday released updated versions of its software for Windows, Mac OS X and Linux that do not contain the bugs. A fixed version of the application for Pocket PCs is forthcoming, according to Skype's security advisory.
Joris Evers writes for CNET News.com
Back to VoIP Special Report
Skype rings changes with standalone VoIP phone
No need for wi-fi or a PC...
Skype goes Mac
Now graphic designers can beta path to Skype's door...
Report slams US VoIP-tapping policy
It'll give hackers a helping hand, say security specialists
Skype sued for patent violation
Net2Phone cries foul...
Vonage shareholders sue over IPO
'Our cash was their exit strategy... '
Stories from around the web...
Skype dreams for developers CNET News.com
Enterprise VoIP: To adopt or not to adopt? Telephony Online
How scalable is your VoIP solution? TechRepublic - free subscription required
Despite the buzz, VOIP still has hurdles to overcome GCN.com
Make your voice heard
silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.
Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.
Extras include complementary passes to silicon.com events and survey prizes such as iPods. Plus, there are the obvious networking opportunities with your fellow panellists.
For more about the Research Panel and how to join, click here
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page