.:[ packet storm ]:.
                         
security in numbers
security in numbers

 ///  File Name:ZDI-10-027.txt
Description:
Zero Day Initiative Advisory 10-027 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Skype. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists with how the OS web-browser passes command line arguments to Skype through the registered 'skype:' protocol handler. Insufficient sanity checking to the /datapath argument allows an attacker to construct a link that will execute Skype with arbitrary arguments. This can be abused to specify a remote configuration storage directory which can be leveraged to glean target user credentials.
Author:TippingPoint
Homepage:http://www.zerodayinitiative.com/
File Size:3574
Last Modified:Mar 11 17:29:44 2010
MD5 Checksum:a5b3d84df1886a5f304313233a95f00f

 .:. Back