Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Permission problem in Skype BETA for linux |
|---|---|
| Date: | Wed, 22 Dec 2004 18:12:36 +0100 |
Date: December 2004 Product: Skype (http://skype.com/) "Skype is free Internet telephony that just works. Skype is for calling other people on their computers or phones. Download Skype and start calling for free all over the world." Affected versions: Linux RPM's version 0.92.0.12, possibly others. (Linux versions are marked as "BETA") Problem Description: During installation a world-writable directory "/usr/share/skype/lang" is created. Impact: The directory (presumably) contains various language files used by the skype application. An attacker could modify these files. It is unknown if this could be used for attacking local users running the skype application. Solution: The problem seems to be fixed in version 0.93.0.3, which is currently available for download from the skype website. History: - Vendor notified on 19-Nov-2004 - Vendor acknowledged problem within 40 minutes - Fixed version available since 21-Dec-2004 -- Peter Conrad Tel: +49 6102 / 80 99 072 [ t]ivano Software GmbH Fax: +49 6102 / 80 99 071 Bahnhofstr. 18 http://www.tivano.de/ 63263 Neu-Isenburg Germany
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: DJB's students release 44 *nix software vulnerability advisories, Steven M. Christey |
|---|---|
| Next by Date: | PHP v4.3.x exploit for Windows., The Warlock |
| Previous by Thread: | [Full-Disclosure] Script Injection in Google Groups Beta, n3td3v |
| Next by Thread: | PHP v4.3.x exploit for Windows., The Warlock |
| Indexes: | [Date] [Thread] [Top] [All Lists] |