PT-2005-4079 · Microsoft+2 · Windows+3
Dcrstic.Ccr
·
Published
2005-10-27
·
Updated
2017-07-11
·
CVE-2005-3267
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Skype versions prior to 1.4.x.84 on Windows
Skype versions prior to 1.3.x.17 on Mac OS
Skype versions prior to 1.2.x.18 on Linux
Skype versions 1.1.x.6 and earlier
Description
The issue is caused by an integer overflow that leads to a heap-based buffer overflow when the Skype client processes crafted network data with a large Object Counter value. This can result in a denial of service, causing the client to crash.
Recommendations
For Windows versions prior to 1.4.x.84, update to version 1.4.x.84 or later.
For Mac OS versions prior to 1.3.x.17, update to version 1.3.x.17 or later.
For Linux versions prior to 1.2.x.18, update to version 1.2.x.18 or later.
For versions 1.1.x.6 and earlier, update to a version later than 1.1.x.6.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux
Apple Macos
Skype
Windows