vendor:
Skype for Linux
by:
Emanuele Gentili (Emgent), Emanuele Acri (Crossbower)
3,3
CVSS
LOW
Denial of Service (CPU 100%) in 'SED' feature, Local Buffer Overflows, QT HTML injection, Pseudo-XSS
N/A
CWE
Product Name: Skype for Linux
Affected Version From: <=2.1 Beta
Affected Version To: <=2.1 Beta
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 8.10, Debian 6.0 Testing
2010
Skype for Linux (<=2.1 Beta) multiple strange behavior
Using multiple times the SED feature can DoS a remote client (CPU 100%), and prevent the normal use of Skype, especially the voice conversations. After the DoS the program must be restarted. Local Bofs when you try to send SMS and call phone numbers that are not well formatted. A BoF occurs also when the string of the previous attack is 89601 characters long. It is possible to inject HTML code in the QT GUI of Skype. The HTML code is not interpreted by the browser, but it is possible to inject javascript code that will be executed by the QT engine.
Mitigation:
Upgrade to the latest version of Skype for Linux