3S Labs Banner

Tuesday, May 22, 2012

Skype Greeting API Crash

It seem like the following code crashes latest version of Skype:


The interfaces look like this:


The crash log looks something like this:


This issue can however only be triggered from a post-authorized state ie. your client must be authorized by the Skype client to use Skype API.

Security Impact of this issue is currently unknown due to uncertainty of exploitation possibility. Even if exploitation is possible (although looks unlikely) the impact will be lower due to local and post-authorized nature of the affected functionality.

1 comment: