Skype plugs hole in VoIP software

By Robert Lemos, CNET News.com
Tuesday, November 16, 2004 10:28 AM
Peer-to-peer phone company Skype has updated its Internet telephony software, patching a critical flaw in its client for Microsoft Windows-based systems.

The vulnerability could allow attackers to take control of a Skype user's PC after the victim clicks on a specially created URL, security information provider Secunia said Monday. By including a long string of characters in the link, the attacker could trigger a memory error known as a buffer overflow that could then be exploited to run a program.

"Successful exploitation may allow execution of arbitrary code," Secunia said. It has ranked the flaw as "highly critical"--its second-highest rating.

Skype acknowledged the security hole in its release notes for the update. "We became aware of a security threat late last week and moved to correct it," said Kelly Larabee, a spokeswoman for Skype. "We encourage users to download the latest version."

Skype's software enables people to use the Internet to place voice calls. Calls to other Internet phone users are free, while calls to traditional phones and mobile phones are charged a per-minute fee. More than 34 million people have downloaded the software, and as many as 1 million people have used the service simultaneously, according to a posting on Skype's Web site.

Skype's voice over Internet Protocol (VoIP) client runs on Windows XP, Mac OS X, Linux and Microsoft PocketPC.

Secunia also recommended that Skype users update to the latest version of the VoIP software.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

OpenAmplify developer's diary Part 4: Using OpenAmplify via SOAP

Web Development

Justin James walks you through the process of using the SOAP interface to OpenAmplify from Visual Studio 2008.


Read more »



When technology costs more than human

Blog thumbnail

Movie director James Cameron waited 15 years for technology to catch up before it was sufficiently advanced for him to create the much-anticipated upcoming film, Avatar.

To be released in..... by Eileen Yu

Read more »

Tags

  1. 3g
  2. 3g third generation
  3. apple inc.
  4. apple iphone
  5. broadband
  6. cellular phones
  7. google inc.
  8. handset
  9. mobile
  10. mobile platforms / communications
  11. mobile / wireless
  12. network
  13. phone
  14. revenue
  15. smart phone
  16. smart phones
  17. software
  18. u.s.
  19. web
  20. wireless