Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Ken.

« VOIP Revenues to Hit $18B | Main | Skype for Business? Gotchas or Opportunities? »

Skype Technologies Skype networking routine heap overflow vulnerability

March 17, Security Focus — Skype Technologies Skype networking routine heap overflow vulnerability. Skype is prone to a heap overflow vulnerability in its networking routines. Analysis: An attacker who sends a stream of specifically crafted network traffic to a Skype client network can cause the client to overwrite part of the heap, including the heap integrity control data. Since the attacker cannot control the address where the data is written, the most likely effect will be that the Skype will abort execution due to an internal error, although other unpredictable behavior is possible. Such a crash will lead to a loss of availability of the Skype application until it is restarted by the user. A complete list of vulnerable products is available in the source advisory. Solution: A fix for Skype for Pocket PC is not currently available. For further solution details: http://www.securityfocus.com/bid/15192/solution Source: http://www.securityfocus.com/bid/15192/references

Technorati Tags




A

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Ken Camp's Bio:

Ken Camp has more than 25 years of experience in information technology. Ken spent 17 years with AT&T and Lucent Technologies successfully designing and implementing voice and data networks. He later worked in the security marketplace and played a key role in early IPSec VPN deployments. As an independent consultant, Ken's primary focal areas include network performance improvement, security practices and the design and deployment of integrated voice and data solutions. He may be contacted at: ken_camp@realtimepublishers.net

line

Blog Roll