Skype for Mac 5.x < 5.1.0.922 Unspecified Remote Code Execution (credentialed check)

medium Nessus Plugin ID 53844

Synopsis

The remote Mac OS X host has an application that allows arbitrary code execution.

Description

According to its version, the instance of Skype installed on the remote Mac OS X host reportedly allows an attacker to send a specially crafted message to a user on the affected host and execute arbitrary code.

Note that by default, such a message would have to come from someone in a user's Skype Contact List.

Solution

Upgrade to Skype for Mac 5.1.0.922 or later.

See Also

http://www.nessus.org/u?6a8cef8d

http://www.nessus.org/u?c36790c1

Plugin Details

Severity: Medium

ID: 53844

File Name: macosx_skype_5_1_0_922.nasl

Version: 1.7

Type: local

Agent: macosx

Published: 5/9/2011

Updated: 7/14/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 5.1

Temporal Score: 3.8

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:skype:skype

Required KB Items: MacOSX/Skype/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 4/14/2011

Vulnerability Publication Date: 5/6/2011

Reference Information

CVE: CVE-2011-2074

BID: 47747