Skype < 1.4.0.84 Multiple Vulnerabilities (uncredentialed check)

This script is Copyright (C) 2006-2016 Tenable Network Security, Inc.


Synopsis :

Arbitrary code can be executed on the remote host.

Description :

The remote host is running Skype, a peer-to-peer voice over IP
software.

The remote version of this software is vulnerable to a heap overflow
in the handling of its data structures. An attacker can exploit this
flaw by sending a specially crafted network packet to UDP or TCP ports
Skype is listening on. A successful exploitation of this flaw will
result in code execution on the remote host.

In addition, Skype has been reported to contain overflows in the
handling of VCards and callto/skype URLs. However, Nessus has not
checked for them.

See also :

http://www.skype.com/security/skype-sb-2005-03.html

Solution :

Upgrade to skype version 1.4.0.84 or later.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.4
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows

Nessus Plugin ID: 21209 ()

Bugtraq ID: 15190
15192

CVE ID: CVE-2005-3265
CVE-2005-3267

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now