>> Skype Multiple URI and VCARD Handling Buffer Overflow Vulnerabilities
Title : Skype Multiple URI and VCARD Handling Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2005-2197 CVE ID : CVE-2005-3265 - CVE-2005-3267
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-10-25
Technical Description
Multiple vulnerabilities were identified in Skype, which could be exploited by remote attackers to execute arbitrary commands or cause a denial of service.
The first issue is due to a buffer overflow error when processing a specially crafted "callto://" or "skype://" URL, which could be exploited by attackers to execute arbitrary commands.
The second vulnerability is due to an error when importing non-standard VCARD files, which could be exploited by attackers to compromise a vulnerable system by convincing a user to import a malicious VCARD.
The third flaw is due to a heap overflow error when handling specially crafted network packets, which could be exploited by remote attackers to execute arbitrary commands or cause a denial of service.