Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct social engineering or other attacks.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=110868557905786&w=2 | issue tracking mailing list third party advisory |
http://marc.info/?l=bugtraq&m=110374568916303&w=2 | issue tracking mailing list third party advisory |
http://www.securityfocus.com/bid/12081 | vendor advisory vdb entry third party advisory broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18644 | vdb entry third party advisory |