Skype for Windows cross-zone code execution
|skype-addvideotochat-code-execution (39754)||High Risk|
Skype could allow a remote attacker to bypass cross-zone restrictions and execute arbitrary code on a vulnerable system, caused by the insecure usage of Internet Explorer when loading content from certain Web sites. Script loaded from the Dailymotion or Metacafe Web site will execute in Internet Explorer's Local Zone instead of the Internet Zone. By persuading a victim to perform a search for a video on the Skype video gallery section of one of the affected Web sites, a remote attacker could inject malicious script into the "Add video to chat" or "Add video to mood" dialog using the "Title" or "Description" video metadata field. An attacker could exploit this vulnerability to execute arbitrary code on the victim's system.
Upgrade to the latest version of Skype (3.8 or later), available from the Skype Web site. See References.
- Aviv Raff On .NET Web site: Skype cross-zone scripting vulnerability.
- Aviv Raff On .NET Web site: No more videos for you. Come back when patch available!.
- Full-Disclosure Mailing List, Thu, 17 Jan 2008 09:59:13 +0200: Skype videomood XSS.
- Skype Web site: Download the latest version of Skype.
- SKYPE-SB/2008-001: Skype Cross Zone Scripting Vulnerability.
- BID-27338: Skype Web Content Zone Remote Code Execution Vulnerability
- CVE-2008-0454: Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 18.104.22.168, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the Add video to chat dialog, aka videomood XSS.
- CVE-2008-0583: Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 22.214.171.124, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Description and unspecified other metadata fields of a Metacafe movie submitted by Metacafe Pro to the Skype video gallery, accessible through a search within the (1) Add video to chat or (2) Add video to mood dialog, a different vector than CVE-2008-0454.
- OSVDB ID: 42863: Skype Internet Explorer Web Control Dailymotion Title Field Cross-zone Scripting
- OSVDB ID: 42864: Skype Internet Explorer Web Control Video Gallery Metacafe Movie Title Cross-zone Scripting
- OSVDB ID: 42868: Skype Metacafe Pro Gallery Submitted Movie Multiple Field Cross-zone Scripting
- US-CERT VU#248184: Skype does not properly filter input from external websites
- US-CERT VU#794236: SkypeFind fails to properly sanitize user-supplied input
- Skype Skype for Windows 126.96.36.199
Jan 17, 2008
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email ignore thisxforceignore this@ignore thisus.ignore thisibm.comignore this