Menu
Skype to fix wormable bug in Mac software

Skype to fix wormable bug in Mac software

A hotfix for the problem has been available since April 14

Skype plans to push out an important update to its Skype for Mac software next week that will fix a big that could be leveraged by hackers looking to build a self-copying worm program.

Details of the flaw haven't been made public, so it's unlikely that anyone is going to write a worm any time soon. But the bug is serious, according to Gordon Maddern, the Australian security researcher who reported the issue to Skype.

"The long and the short of it is that an attacker needs only to send a victim a message and they can gain remote control of the victims Mac," Maddern wrote in a blog post. "It is extremely wormable and dangerous."

According to Skype, any attack that exploited it would involve sending a maliciously crafted message to someone on the attacker's Skype Contact List. The flaw does not affect Windows or Linux users, Skype Chief Information Security Officer Adrian Asher wrote in a blog post on the issue.

Skype will push out an update to its Skype for Mac software early next week, which means that all Mac OS users should be offered the fix within days.

But security-conscious people can already download a "hotfix" that Skype released on April 14. However, to date, Skype hasn't pushed this patch out to its users. Because "there were no reports of this vulnerability being exploited in the wild, we did not prompt our users to install this update," Asher said.

Mac users who want the fix now can click on Skype --> Check for Updates, or they can download the latest update from Skype's website. Otherwise they'll be prompted to upload the fix early next week.

Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com

Follow Us

Join the ARN newsletter!

Error: Please check your email address.

Tags patchesInternet-based applications and servicesskypeMac OSapplicationssecuritysoftwareoperating systemsinternetApple

Upcoming

Slideshows

IN PICTURES: Nutanix's .NEXT channel event in Sydney (+20 photos)

IN PICTURES: Nutanix's .NEXT channel event in Sydney (+20 photos)

Nutanix recently held its customer and channel event, .NEXT, in Sydney. The event, held at the Sheraton on the Park saw attendance from more than 150 channel and technology partners and customers. It was the first in a series of events Nutanix is holding in A/NZ in August and September, the objective of which is to brief partners and customers on “what’s next” in the design and management of datacentre technology.

IN PICTURES: Nutanix's .NEXT channel event in Sydney (+20 photos)
IN PICTURES: EDGE 2015 sponsor debrief (+23 photos)

IN PICTURES: EDGE 2015 sponsor debrief (+23 photos)

Some of the sponsors of ARN's inaugural EDGE 2015 event got together at the ARN office for a debrief of the event. Over some drinks and cheese, these attendees got an update on some key statistics that arose from the EDGE event and discussed potential topics and improvements that can be made at next year's event.

IN PICTURES: EDGE 2015 sponsor debrief (+23 photos)
IN PICTURES: ARN Distributor Roundtable, Sydney, 26.08.15 (+26 photos)

IN PICTURES: ARN Distributor Roundtable, Sydney, 26.08.15 (+26 photos)

ARN hosted a distributor roundtable at Cafe Del Mar in Sydney, at which attendees and their partners discussed the changing role of the traditional IT distributor. They spoke about the challenges of digital disruption, the blurring lines of the channel in the age of digital transformation, and examined the ever-evolving business models. This roundtable was sponsored by Distribution Central, Exclusive Networks, Rhipe, and Hemisphere Technologies. Photos by ARN Editorial Director, Mike Gee.

IN PICTURES: ARN Distributor Roundtable, Sydney, 26.08.15 (+26 photos)

iasset.com is a channel management ecosystem that automates all major aspects of the entire sales, marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.

Show Comments