Skype Buffer Overflow Vulnerability

Security portion of Skype’s web site mentions a vulnerability in Skype-specific URI and VCARD import handling. The report says that this problem is a subsidiary effect of documented Borland Delphi issue.

It looks like that Skype can be made to execute arbitrary code through a buffer overflow when the software is called upon to handle malformed URLs that are in form of callto:// and skype://. In addition, Skype can be made to execute arbitrary code during importation of a VCARD that is in a specific non-standard format.

Skype for Windows releases 1.1.*.0 through 1.4.*.83 are vulnerable to these problems. For the official fix, please visit SKYPE-SB/2005-002.