Mitigate Skype bug reported by Purehacking.com which only affects MacOSX. We do not have confirmation of the vulnerability in Skype, the version number or system details related to the reports. The post on the site has a spelling error resulting in us proceeding with caution but think the report may be credible since it has been reported elsewhere including Sans ISC.
This makes this the perfect opportunity to review several ways to use Skype in a safe manner, the most important being to "Quit" the application when done. These steps we think can mitigate the vulnerability in Skype reported.
Currently at this time we are recommending the following settings in Skype.
- Make sure that you are running the most up to date client, 5.1.0.922
- If not you need to goto Skype.com and manually install it now, Check for updates will not install it.
- Make sure when using SKYPE you are not Administrator for that system.
- Do not install Skype on any servers.
- Quit Skype when you are done, do not leave it open.
- Under Skype>Preferences>General disable "Automatically Accept incoming files."
- Under Skype>Preferences>General disable "Open safe files after receiving."
- Under Skype>Preferences>General set "Downloads" as the file folder.
- Under Skype>Preferences>General disable "Show Address Book Contacts."
- Under Skype>Preferences>Privacy set "Show picture", "Allow calls from", "Receive Calls to my online number from" and "Allow messages from" all to Contacts.
- Under Skype>Preferences>Privacy set "Allow video screen sharing from" to "Nobody.
- Under Skype>Preferences>Privacy disable "Show my status on the web."
- Under Skype>Preferences>Calls set "Incoming Calls" to "Do Nothing"
- Under Skype>Preferences>Calls disable "Start video automatically at the beginning of a call."
- Under Skype>Preferences>Advanced disable "Use Skype Access to connect to Wi-Fi hotspots."
Based on reporting we think that these steps will allow you to mitigate the issue reported. Dependent on how you use Skype you may alter the configuration but this will change the Risk profile. We do not consider Skype a secure form of communication but a useful tool.
Skype did released an hot fix, version 10.1.0.922, on April 14th. You need to install it by downloading it directly from Skype.com. More information posted on the Skype Blog.
Update 5.1.0.922 released to stable channel for update delivery.
Skype has released version 5.1.0.935 to the stable channel. The update can be applied using "Check for Updates" in Skype.