PT-2005-4078 · Microsoft · Skype For Windows+1
Mark Rowe
·
Publicado
2005-10-27
·
Atualizado
2017-07-11
·
CVE-2005-3265
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Skype for Windows versions 1.1.x.0 through 1.4.x.83
Description
The issue allows remote attackers to execute arbitrary code via (1) "callto://" and (2) "skype://" links, or (3) a non-standard VCARD, possibly due to an underlying error in the
SysUtils.WideFmtStr Delphi routine.Recommendations
For Skype for Windows versions 1.1.x.0 through 1.4.x.83, consider disabling the handling of "callto://" and "skype://" links, as well as non-standard VCARDs, until a patch is available. Restrict access to the
SysUtils.WideFmtStr Delphi routine to minimize the risk of exploitation.Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Skype
Skype For Windows