First published: Fri May 19 2006(Updated: )
Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a URL that contains certain command-line switches.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Skype | =0.98.0.04 | |
Microsoft Skype | =1.0.0.9 | |
Microsoft Skype | =1.0.0.10 | |
Microsoft Skype | =1.0.0.18 | |
Microsoft Skype | =1.0.0.29 | |
Microsoft Skype | =1.0.0.94 | |
Microsoft Skype | =1.0.0.97 | |
Microsoft Skype | =1.0.0.100 | |
Microsoft Skype | =1.1.0.0 | |
Microsoft Skype | =1.4.0.83 | |
Microsoft Skype | =2.0 | |
Microsoft Skype | =2.0.104 | |
Microsoft Skype | =2.5 | |
Microsoft Skype | =2.5.78 | |
Microsoft Windows | ||
All of | ||
Any of | ||
Microsoft Skype | <2.0.0.105 | |
Microsoft Skype | >=2.5.0.0<2.5.0.79 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2312 is considered a high severity vulnerability due to the potential for remote file downloads by unauthorized attackers.
To fix CVE-2006-2312, users should upgrade to the latest version of Skype that is not affected by this vulnerability.
CVE-2006-2312 affects Skype versions 2.0.*.104 and 2.5.*.0 through 2.5.*.78.
CVE-2006-2312 enables remote authorized attackers to inject arguments via a specially crafted URL, leading to arbitrary file downloads.
Mitigations for CVE-2006-2312 include monitoring incoming links and avoiding the use of legacy Skype versions that are known to be vulnerable.