Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a dangerous extension that uses a different case.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securitytracker.com/id?1020201 | vdb entry |
http://secunia.com/advisories/30547 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43044 | vdb entry |
http://www.vupen.com/english/advisories/2008/1749/references | vdb entry |
http://www.securityfocus.com/bid/29553 | vdb entry |
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=711 | third party advisory |
http://www.skype.com/security/skype-sb-2008-003.html | patch |