First published: Thu Oct 27 2005(Updated: )
Integer overflow in Skype client before 1.4.x.84 on Windows, before 1.3.x.17 on Mac OS, before 1.2.x.18 on Linux, and 1.1.x.6 and earlier allows remote attackers to cause a denial of service (crash) via crafted network data with a large Object Counter value, which leads to a resultant heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Skype | =0.92.0.12 | |
Microsoft Skype | =0.93.0.3 | |
Microsoft Skype | =0.98.0.04 | |
Microsoft Skype | =1.0.0.1 | |
Microsoft Skype | =1.0.0.7 | |
Microsoft Skype | =1.0.0.9 | |
Microsoft Skype | =1.0.0.10 | |
Microsoft Skype | =1.0.0.18 | |
Microsoft Skype | =1.0.0.29 | |
Microsoft Skype | =1.0.0.94 | |
Microsoft Skype | =1.0.0.97 | |
Microsoft Skype | =1.0.0.100 | |
Microsoft Skype | =1.1.0.0 | |
Microsoft Skype | =1.1.0.20 | |
Microsoft Skype | =1.1.06 | |
Microsoft Skype | =1.2.0.17 | |
Microsoft Skype | =1.3.0.16 | |
Microsoft Skype | =1.4.0.83 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3267 has a severity that can lead to a denial of service due to a crash of the Skype client.
To address CVE-2005-3267, users should upgrade to a version of Skype that is 1.4.x.84 or newer.
CVE-2005-3267 is caused by an integer overflow resulting from large Object Counter values in crafted network data.
Versions of Skype prior to 1.4.x.84 on Windows, 1.3.x.17 on macOS, and 1.2.x.18 on Linux are affected by CVE-2005-3267.
CVE-2005-3267 is classified as a denial of service vulnerability.