SECUNIA ADVISORY ID: SA28791
VERIFY ADVISORY: http://secunia.com/advisories/28791/
CRITICAL: Highly critical
IMPACT: System access
SOFTWARE:
Skype for Windows 3.x - http://secunia.com/product/12919/
Skype for Windows 2.x - http://secunia.com/product/7268/
Skype for Windows 1.x - http://secunia.com/product/4250/
DESCRIPTION: An update has been released for Skype, which implements security enhancements to prevent compromise of users' systems. Skype uses the Internet Explorer web control to render HTML from certain websites (e.g. DailyMotion, Metacafe, and SkypeFind). As the content is rendered in the "Local Machine" security zone, this allows execution of arbitrary script code on a user's system via script insertion vulnerabilities present in these websites.
Read More...
Skype Cross-Zone Scripting Security Enhancement
Posted on Wednesday, February 06, 2008 @ 16:14:53 CST in Security
|
HTML 5 is on the horizon
Posted on Tuesday, February 05, 2008 @ 16:21:34 CST in Internet
|
Web address system faces changes
Posted on Monday, February 04, 2008 @ 22:03:53 CST in Internet nb1 writes:
|
NukeSentinel(tm) 2.5.16 Released (Refresh Release)
Posted on Sunday, February 03, 2008 @ 19:57:13 CST in NukeSentinel (tm)
|
Competition Quiz To Celebrate 5 years
Posted on Saturday, February 02, 2008 @ 10:35:30 CST in Announcements lippylion writes:
|
Coppermine Photo Gallery Multiple Vulnerabilities
Posted on Wednesday, January 30, 2008 @ 22:02:53 CST in Security
|