SECUNIA ADVISORY ID: SA28791
VERIFY ADVISORY: http://secunia.com/advisories/28791/
CRITICAL: Highly critical
IMPACT: System access
SOFTWARE:
Skype for Windows 3.x - http://secunia.com/product/12919/
Skype for Windows 2.x - http://secunia.com/product/7268/
Skype for Windows 1.x - http://secunia.com/product/4250/
DESCRIPTION: An update has been released for Skype, which implements security enhancements to prevent compromise of users' systems. Skype uses the Internet Explorer web control to render HTML from certain websites (e.g. DailyMotion, Metacafe, and SkypeFind). As the content is rendered in the "Local Machine" security zone, this allows execution of arbitrary script code on a user's system via script insertion vulnerabilities present in these websites.
Read More...
Skype Cross-Zone Scripting Security Enhancement
Posted on Wednesday, February 06, 2008 @ 16:14:53 CST in Security
|
Coppermine Photo Gallery Multiple Vulnerabilities
Posted on Wednesday, January 30, 2008 @ 22:02:53 CST in Security
|
IrfanView FlashPix Plug-in Memory Corruption Vulnerability
Posted on Tuesday, January 29, 2008 @ 17:12:21 CST in Security
|
Nuke Security 2008
Posted on Tuesday, January 29, 2008 @ 09:18:10 CST in Security Evaders99 writes:
|
phpBB Private Message Deletion Cross-Site Request Forgery
Posted on Friday, January 25, 2008 @ 20:29:15 CST in Security
|
Seagull PHP Framework *files* Information Disclosure
Posted on Friday, January 25, 2008 @ 20:25:21 CST in Security
|