Version: 2008
  • On GameSpot: Handheld Xbox coming...eventually.

November 15, 2004 2:58 PM PST

Skype plugs hole in VoIP software

  • Post a comment
Peer-to-peer phone company Skype has updated its Internet telephony software, patching a critical flaw in its client for Microsoft Windows-based systems.

The vulnerability could allow attackers to take control of a Skype user's PC after the victim clicks on a specially created URL, security information provider Secunia said Monday. By including a long string of characters in the link, the attacker could trigger a memory error known as a buffer overflow that could then be exploited to run a program.

"Successful exploitation may allow execution of arbitrary code," Secunia said. It has ranked the flaw as "highly critical"--its second-highest rating.

Skype acknowledged the security hole in its release notes for the update. "We became aware of a security threat late last week and moved to correct it," said Kelly Larabee, a spokeswoman for Skype. "We encourage users to download the latest version."

Skype's software enables people to use the Internet to place voice calls. Calls to other Internet phone users are free, while calls to traditional phones and mobile phones are charged a per-minute fee. More than 34 million people have downloaded the software, and as many as 1 million people have used the service simultaneously, according to a posting on Skype's Web site.

Skype's voice over Internet Protocol (VoIP) client runs on Windows XP, Mac OS X, Linux and Microsoft PocketPC.

Secunia also recommended that Skype users update to the latest version of the VoIP software.

See more CNET content tagged:
Skype, VoIP, telephone company, P2P, security

advertisement
Click Here

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (0.07%) 0.02 29.01
Dow Jones Industrials (0.20%) 20.03 10,246.97
S&P 500 (-0.01%) -0.07 1,093.01
NASDAQ (-0.14%) -2.98 2,151.08
CNET TECH (0.21%) 3.30 1,571.59
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right