Release date:
Updated on:
Affected Systems:
Skype 5.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51988
Skype is a free global voice communication software.
Skype has the local information leakage vulnerability in implementation. Even if you enable the "no history" option in the "Keep history for" setting, or manually use the "Clear history" button to delete it, local attackers can still exploit this vulnerability to obtain sensitive information.
<* Source: anonymous
Link: http://seclists.org/fulldisclosure/2012/Feb/208
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
In Windows XP, go to "C: \ Documents ents and Settings \ % username % \ Application Data \ Skype \ % Skype user name %" and OPEN main. db in a text editor.
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Skype
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.skype.com/