CVE-2005-3265

Description

Buffer overflow in Skype for Windows 1.1.x.0 through 1.4.x.83 allows remote attackers to execute arbitrary code via (1) callto:// and (2) skype:// links, or (3) a non-standard VCARD, possibly due to an underlying error in the SysUtils.WideFmtStr Delphi routine.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
35.548

Associated Vulnerability

VulnerabilityOS Platform
Update to Skype Technologies Skype 1.4.0.84Windows
update skype 1.4.0.83 to latest versionWindows
Update to Skype Technologies Skype 1.4.0.84 (For Ubuntu)Linux
update skype 1.4.0.83 to latest version (For Ubuntu)Linux
Update to Skype Technologies Skype 1.4.0.84 (For Debian)Linux
update skype 1.4.0.83 to latest version (For Debian)Linux
Update to Skype Technologies Skype 1.4.0.84 (For Centos)Linux
update skype 1.4.0.83 to latest version (For Centos)Linux
Update to Skype Technologies Skype 1.4.0.84 (For RedHat)Linux
update skype 1.4.0.83 to latest version (For RedHat)Linux
Update to Skype Technologies Skype 1.4.0.84 (For Suse)Linux
update skype 1.4.0.83 to latest version (For Suse)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343283Skype (8.133.0.202) (Manual Upload Required)
PATCH-343283Skype (8.133.0.202) (Manual Upload Required)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234