Skype for Windows cross-zone code execution
| skype-addvideotochat-code-execution (39754) |
Description:
Skype could allow a remote attacker to bypass cross-zone restrictions and execute arbitrary code on a vulnerable system, caused by the insecure usage of Internet Explorer when loading content from certain Web sites. Script loaded from the Dailymotion or Metacafe Web site will execute in Internet Explorer's Local Zone instead of the Internet Zone. By persuading a victim to perform a search for a video on the Skype video gallery section of one of the affected Web sites, a remote attacker could inject malicious script into the "Add video to chat" or "Add video to mood" dialog using the "Title" or "Description" video metadata field. An attacker could exploit this vulnerability to execute arbitrary code on the victim's system.
*CVSS:
| Base Score: | 9.3 |
| Access Vector: | Network |
| Access Complexity: | Medium |
| Authentication: | None |
| Confidentiality Impact: | Complete |
| Integrity Impact: | Complete |
| Availability Impact: | Complete |
| Temporal Score: | 7.3 |
| Exploitability: | Proof-of-Concept |
| Remediation Level: | Official-Fix |
| Report Confidence: | Confirmed |
Consequences:
Gain Access
Remedy:
Upgrade to the latest version of Skype (3.8 or later), available from the Skype Web site. See References.
References:
- Aviv Raff On .NET Web site: Skype cross-zone scripting vulnerability.
- Aviv Raff On .NET Web site: No more videos for you. Come back when patch available!.
- Full-Disclosure Mailing List, Thu, 17 Jan 2008 09:59:13 +0200: Skype videomood XSS.
- Skype Web site: Download the latest version of Skype.
- SKYPE-SB/2008-001: Skype Cross Zone Scripting Vulnerability.
- BID-27338: Skype Web Content Zone Remote Code Execution Vulnerability
- CVE-2008-0454: Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the Add video to chat dialog, aka videomood XSS.
- CVE-2008-0583: Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Description and unspecified other metadata fields of a Metacafe movie submitted by Metacafe Pro to the Skype video gallery, accessible through a search within the (1) Add video to chat or (2) Add video to mood dialog, a different vector than CVE-2008-0454.
- US-CERT VU#248184: Skype does not properly filter input from external websites
- US-CERT VU#794236: SkypeFind fails to properly sanitize user-supplied input
- VUPEN/ADV-2008-0194: Skype Video Gallery Browser Cross Zone Scripting Vulnerabilities
Platforms Affected:
- Skype Skype for Windows 3.6.0.244
Reported:
Jan 17, 2008
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
* According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall IBM be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
