heise online IT news, features and forums at heise online UK
7 February 2008, 12:24

Skype closes scripting holes in Windows client

Skype has released an update for its eponymous VoIP client to remedy a cross-zone scripting vulnerability and other bugs. The vulnerability allows manipulated videos from Dailymotion and Metacafe to inject malicious code. While awaiting the release of this update, Skype has been blocking access to these partner websites. Now, the update forces all HTML content to run in the internet zone instead of the local zone.

Advertisement

The new version 3.6.0.248 also contains a blacklist and a whitelist to determine which programs have access to Skype's public API. In addition, connection speeds from the Skype network to "restrictive network environments" have been improved. The new version of the client also fixes several other flaws. Users can either use Skype's update function or download the software manually.

See also:

(mba)

  • Bookmark & Share
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit