Skype Logo
Buy Skype Credit · Help ·
  • Download
  • Use Skype
  • Business
  • Shop
  • Account
Villu Arak

(Resolved) Skype Cross Zone Scripting Vulnerability

By My status Villu Arak on January 18, 2008 in Skype security features.

A vulnerability that allowed an attacker to execute arbitrary code on a Skype user's Windows PC without their consent has been discovered in Skype and on Dailymotion, the video-sharing site where Skype users can download video clips and add them to their Skype moods and chats.

The vulnerability had the potential to affect users of Skype 3.5 and 3.6 for Windows who, in Skype's video gallery, navigated to a Dailymotion video with a specially crafted title.

The issue, demonstrated by security researchers as a proof of concept, was neutralized before actual attackers took advantage of it, therefore Skype users are unlikely to have been affected. Skype has temporarily disabled users' ability to add videos from the Dailymotion gallery until an official fix has been made available. In turn, Dailymotion is addressing the vulnerability on their web site.

For a more detailed description of the issue, please see the most recent Skype Security Bulletin.

Update: We've also temporarily disabled the ability to add videos from the Metacafe video gallery. Both Dailymotion and Metacafe videos will be re-enabled as soon as an official fix has been made available.

- - -

Final update on Feb. 6, 2008 - the issue has been resolved. Please see today's post for more information.

Bookmark and Share

View blog reactions

Comments

Hang ups
During a Skype call ...I experience a hang up frequently ...I make the call.... everything is fine for a few minutes and then the call hangs up leaving myself and my friends frustrated...
I need technical support....I have downloaded the newest version for Mac and I am tired of being hung up on...
I cannot find a solution on the technical support side either.

dotty777 | Thursday, Mar 26

Comment on this post

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Please read our comment guidelines before posting your comment.

Skype Blogs
  • Share Skype Blog
  • Heartbeat
  • Developer Zone
  • Business
  • Skype Gear
  • Security
  • Garage
  • Mac
  • Linux
  • Eesti keeles
  • 日本語
  • Česky
  • Deutsch
  • Français
  • Italiano
  • Brasil
  • United Kingdom
  • Polski
  • United States
  • 한국어

Recent posts

  • Cross-Site Request Forgery (CSRF) Vulnerability
  • Skype Lottery Scam Alert
  • [RESOLVED] Phishing emails
  • Skype misidentified as malware
  • Trojan downloader alert
  • Skype cross-zone scripting vulnerability now fixed
  • (Resolved) Skype Cross Zone Scripting Vulnerability
  • Vulnerability in Skype for Windows versions older than 3.6.x.216
  • Password stealer
  • Fake malware alert

Archives

  • April 2009
  • December 2008
  • July 2008
  • April 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • February 2007
  • January 2007
  • December 2006
  • May 2006
  • March 2006
  • February 2006
  • October 2005
  • May 2005

Subscribe to this blog
What? Tell me more…

using RSS Subscribe
via Bloglines Subscribe in Bloglines
using Newsgator Subscribe in NewsGator Online
with MyYahoo
with Google Add to Google
with MyAOL Add to My AOL
with netvibes Add to Netvibes
About us · Partners · Jobs · Prices · Security
Privacy policy · Legal · © 2009 Skype Limited