CVE-2005-3267

Description

Integer overflow in Skype client before 1.4.x.84 on Windows, before 1.3.x.17 on Mac OS, before 1.2.x.18 on Linux, and 1.1.x.6 and earlier allows remote attackers to cause a denial of service (crash) via crafted network data with a large Object Counter value, which leads to a resultant heap-based buffer overflow.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
18.243

Associated Vulnerability

VulnerabilityOS Platform
Update to Skype Technologies Skype 1.4.0.84Windows
update skype 1.4.0.83 to latest versionWindows
Update to Skype Technologies Skype 1.4.0.84 (For Ubuntu)Linux
update skype 1.4.0.83 to latest version (For Ubuntu)Linux
Update to Skype Technologies Skype 1.4.0.84 (For Debian)Linux
update skype 1.4.0.83 to latest version (For Debian)Linux
Update to Skype Technologies Skype 1.4.0.84 (For Centos)Linux
update skype 1.4.0.83 to latest version (For Centos)Linux
Update to Skype Technologies Skype 1.4.0.84 (For RedHat)Linux
update skype 1.4.0.83 to latest version (For RedHat)Linux
Update to Skype Technologies Skype 1.4.0.84 (For Suse)Linux
update skype 1.4.0.83 to latest version (For Suse)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343283Skype (8.133.0.202) (Manual Upload Required)
PATCH-343283Skype (8.133.0.202) (Manual Upload Required)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234