Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

August 23rd, 2011, 13:57 GMT · By

Skype Disputes Severity of XSS Vulnerability

SHARE:

Adjust text size:


New cross-site scripting vulnerability identified in Skype
Enlarge picture
Skype disputes the severity of a new cross-site scripting vulnerability identified in its VoIP client and claims that it cannot be used to do more than change the appearance of text.

The vulnerability was discovered by an Armenian security researcher named Levent Kayan, aka noptrix, who recently identified similar flaws in instant messaging clients.

"Skype suffers from a persistent code injection vulnerability due to a lack of input validation and output sanitization of following profile entries: home, office, mobile," the researcher explains in his advisory.

An attacker can exploit the vulnerability to inject HTML or JavaScript code into a Skype profile with yet-to-be determined consequences. At the very least, at attacker could include a malicious link and encourage users to click on it.

HTML injection into Skype profile fields
Enlarge picture
Skype claims that the bug's impact is very limited and has little to no security implications. "We have had this reported to us by various media outlets and have confirmed that the person is mistaken, this is not a web window and while it does cause a phone number to be underlined, does nothing other than this" a spokeswoman said.

Kayan responded by stressing that any HTML tag can be inserted into the vulnerable profile fields, not only the one used to link text. He also points out that this vulnerability is located in the same field as another one that he reported to Skype back in July.

It appears that instead of fixing the previous flaw directly on the client by blocking HTML input in the profile fields, the company chose to sanitize the server output.

"Does it make sense to allow users to 'embed' HTML code in their Skype profile and especially in those 'phone number' fields?" the researcher asks. It seems not, because on Windows and Mac this is not possible. Only the Skype Linux client allows this functionality.

TELL US WHAT YOU THINK:

1,137 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


New Account Hijacking Vulnerability Found in Skype

Cross-Site Scripting Vulnerability Found in Skype

Session Hijacking Vulnerability Identified in ICQ

READER COMMENTS:


Comment #1 by: orly on 23 Aug 2011, 16:22 UTC reply to this comment

http://www.noptrix.net/tmp/skype_xss.png

Orly?

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM