- http://www.skype.com...b-2008-003.html
Impact: Exploitation of this issue allows an attacker to execute arbitrary code on the targeted victim's machine. An attacker would need to construct a malicious file: URI and send it to the intended victim. Upon clicking the link execution of arbitrary code on the victim's machine will be possible.
Affected software: ...The following Skype clients are vulnerable to this attack:
Skype for Windows: All releases prior to and including 3.8.*.115
Solution: Skype has fixed the vulnerability in version 3.8.0.139
Download:
x86 platform, Microsoft Windows 2000 or Microsoft Windows XP: http://www.skype.com.../skype/windows/
x86 platform, Linux: http://www.skype.com...ad/skype/linux/
PPC and x86 platforms, Mac OS X v10.3.9 or later: http://www.skype.com...d/skype/macosx/
Pocket PC platform, Microsoft Windows Mobile 2003: http://www.skype.com...skype/pocketpc/
> http://nvd.nist.gov/...e=CVE-2008-1805
Original release date: 6/6/2008
