CVE-2008-2545
06.06.2008, 22:32
Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a dangerous extension that uses a different case.Enginsight
| Vendor | Product | Version |
|---|---|---|
| skype_technologies | skype | 𝑥 ≤ 3.8.0.115 |
| skype_technologies | skype | 3.0.0.106:beta |
| skype_technologies | skype | 3.0.0.123:beta |
| skype_technologies | skype | 3.0.0.137:beta |
| skype_technologies | skype | 3.0.0.154:beta |
| skype_technologies | skype | 3.0.0.190 |
| skype_technologies | skype | 3.0.0.198 |
| skype_technologies | skype | 3.0.0.205 |
| skype_technologies | skype | 3.0.0.209 |
| skype_technologies | skype | 3.0.0.214 |
| skype_technologies | skype | 3.0.0.216 |
| skype_technologies | skype | 3.0.0.217 |
| skype_technologies | skype | 3.0.0.218 |
| skype_technologies | skype | 3.1.0.112:beta |
| skype_technologies | skype | 3.1.0.134:beta |
| skype_technologies | skype | 3.1.0.144 |
| skype_technologies | skype | 3.1.0.147 |
| skype_technologies | skype | 3.1.0.150 |
| skype_technologies | skype | 3.1.0.152 |
| skype_technologies | skype | 3.2.0.53:beta |
| skype_technologies | skype | 3.2.0.63:beta |
| skype_technologies | skype | 3.2.0.82:beta |
| skype_technologies | skype | 3.2.0.115:beta |
| skype_technologies | skype | 3.2.0.145 |
| skype_technologies | skype | 3.2.0.148 |
| skype_technologies | skype | 3.2.0.152 |
| skype_technologies | skype | 3.2.0.158 |
| skype_technologies | skype | 3.2.0.163 |
| skype_technologies | skype | 3.2.0.175 |
| skype_technologies | skype | 3.5.0.107:beta |
| skype_technologies | skype | 3.5.0.158:beta |
| skype_technologies | skype | 3.5.0.178:beta |
| skype_technologies | skype | 3.5.0.202 |
| skype_technologies | skype | 3.5.0.214 |
| skype_technologies | skype | 3.5.0.229 |
| skype_technologies | skype | 3.5.0.234 |
| skype_technologies | skype | 3.5.0.239 |
| skype_technologies | skype | 3.6.0.127:beta |
| skype_technologies | skype | 3.6.0.159:beta |
| skype_technologies | skype | 3.6.0.216 |
| skype_technologies | skype | 3.6.0.244 |
| skype_technologies | skype | 3.6.0.248 |
| skype_technologies | skype | 3.8.0.96:beta |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References