← Back

CVE-2008-2545

nvd nist
Published: Jun 6, 2008Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a dangerous extension that uses a different case.

Affected (43)

Skype
Configuration A
43 vulnerable
Vulnerable SoftwareAffected Versions
Skype Technologies
Up to 3.8.0.115
Version 3.0.0.106 beta
Version 3.0.0.123 beta
Version 3.0.0.137 beta
Version 3.0.0.154 beta
Version 3.0.0.190
Version 3.0.0.198
Version 3.0.0.205
Version 3.0.0.209
Version 3.0.0.214
Version 3.0.0.216
Version 3.0.0.217
Version 3.0.0.218
Version 3.1.0.112 beta
Version 3.1.0.134 beta
Version 3.1.0.144
Version 3.1.0.147
Version 3.1.0.150
Version 3.1.0.152
Version 3.2.0.115 beta
Version 3.2.0.145
Version 3.2.0.148
Version 3.2.0.152
Version 3.2.0.158
Version 3.2.0.163
Version 3.2.0.175
Version 3.2.0.53 beta
Version 3.2.0.63 beta
Version 3.2.0.82 beta
Version 3.5.0.107 beta
Version 3.5.0.158 beta
Version 3.5.0.178 beta
Version 3.5.0.202
Version 3.5.0.214
Version 3.5.0.229
Version 3.5.0.234
Version 3.5.0.239
Version 3.6.0.127 beta
Version 3.6.0.159 beta
Version 3.6.0.216
Version 3.6.0.244
Version 3.6.0.248
Version 3.8.0.96 beta

References (14)

Timeline

No history available yet.