{"id":2698,"date":"2011-05-07T08:41:43","date_gmt":"2011-05-07T07:41:43","guid":{"rendered":"http:\/\/blog.intego.com\/?p=2698"},"modified":"2011-05-07T08:41:43","modified_gmt":"2011-05-07T07:41:43","slug":"skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/","title":{"rendered":"Skype Zero-Day Vulnerability: They Knew About It, Issued Fix, Didn&#8217;t Tell Anyone"},"content":{"rendered":"<p>Security researchers Pure Hacking recently <a href=\"http:\/\/www.purehacking.com\/blogs\/gordon-maddern\/skype-0day-vulnerabilitiy-discovered-by-pure-hacking\">announced that they discovered a zero-day vulnerability in Skype 5 for Mac<\/a>. This vulnerability could allow a malicious user to send a specially crafted message to another Skype user, and then execute code an the latter Mac.<\/p>\n<p>All well and good. <\/p>\n<p>Skype responded to them that this would soon be fixed, but now it turns out that <a href=\"http:\/\/blogs.skype.com\/security\/2011\/05\/security_vulnerability_in_mac.html\">Skype fixed this issue on April 14<\/a>, yet didn&#8217;t release the update. They say that a fix will be available next week in another update, but if they already have an internal build fixing the problem &#8211; one they made three weeks ago &#8211; why didn&#8217;t they tell anyone? They say, &#8220;As there were no reports of this vulnerability being exploited in the wild, we did not prompt our users to install this update,&#8221; but when vulnerabilities are exploited in the wild, it&#8217;s better that software be updated before then than to try and get users to update after.<\/p>\n<p>This is an irresponsible action on Skype&#8217;s part. Every company has a responsibility to users to issue security updates as soon as possible, and not sit on them just because the vulnerabilities are not yet exploited in the wild. Skype cannot be sure this vulnerability has not been exploited anyway; unless they&#8217;re monitoring every user&#8217;s activity, which we hope is not the case.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers found a vulnerability in Skype for Mac. Skype claims that they knew about it, fixed it, but hadn&#8217;t told anyone. <\/p>\n","protected":false},"author":3,"featured_media":2496,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[13],"tags":[122,144],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Security researchers found a vulnerability in Skype for Mac. Skype claims that they knew about it, fixed it, but hadn&#039;t told anyone.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Skype Zero-Day Vulnerability: They Knew About It, Issued Fix, Didn&#039;t Tell Anyone  - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Security researchers found a vulnerability in Skype for Mac. Skype claims that they knew about it, fixed it, but hadn&#039;t told anyone.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2011-05-07T07:41:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/04\/skype.png\" \/>\n\t<meta property=\"og:image:width\" content=\"128\" \/>\n\t<meta property=\"og:image:height\" content=\"128\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Peter James\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/04\/skype.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/04\/skype.png\",\"width\":\"128\",\"height\":\"128\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/\",\"name\":\"Skype Zero-Day Vulnerability: They Knew About It, Issued Fix, Didn't Tell Anyone - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#primaryimage\"},\"datePublished\":\"2011-05-07T07:41:43+00:00\",\"dateModified\":\"2011-05-07T07:41:43+00:00\",\"description\":\"Security researchers found a vulnerability in Skype for Mac. Skype claims that they knew about it, fixed it, but hadn't told anyone.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Skype Zero-Day Vulnerability: They Knew About It, Issued Fix, Didn&#8217;t Tell Anyone\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\"},\"headline\":\"Skype Zero-Day Vulnerability: They Knew About It, Issued Fix, Didn&#8217;t Tell Anyone\",\"datePublished\":\"2011-05-07T07:41:43+00:00\",\"dateModified\":\"2011-05-07T07:41:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#webpage\"},\"wordCount\":234,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/04\/skype.png\",\"keywords\":[\"Skype\",\"Vulnerability\"],\"articleSection\":[\"Security &amp; Privacy\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\",\"name\":\"Peter James\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"caption\":\"Peter James\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Security researchers found a vulnerability in Skype for Mac. Skype claims that they knew about it, fixed it, but hadn't told anyone.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/","og_locale":"en_US","og_type":"article","og_title":"Skype Zero-Day Vulnerability: They Knew About It, Issued Fix, Didn't Tell Anyone  - The Mac Security Blog","og_description":"Security researchers found a vulnerability in Skype for Mac. Skype claims that they knew about it, fixed it, but hadn't told anyone.","og_url":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/","og_site_name":"The Mac Security Blog","article_published_time":"2011-05-07T07:41:43+00:00","og_image":[{"width":"128","height":"128","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/04\/skype.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Peter James","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/04\/skype.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/04\/skype.png","width":"128","height":"128"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/","name":"Skype Zero-Day Vulnerability: They Knew About It, Issued Fix, Didn't Tell Anyone - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#primaryimage"},"datePublished":"2011-05-07T07:41:43+00:00","dateModified":"2011-05-07T07:41:43+00:00","description":"Security researchers found a vulnerability in Skype for Mac. Skype claims that they knew about it, fixed it, but hadn't told anyone.","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Skype Zero-Day Vulnerability: They Knew About It, Issued Fix, Didn&#8217;t Tell Anyone"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116"},"headline":"Skype Zero-Day Vulnerability: They Knew About It, Issued Fix, Didn&#8217;t Tell Anyone","datePublished":"2011-05-07T07:41:43+00:00","dateModified":"2011-05-07T07:41:43+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#webpage"},"wordCount":234,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/04\/skype.png","keywords":["Skype","Vulnerability"],"articleSection":["Security &amp; Privacy"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/skype-zero-day-vulnerability-they-knew-about-it-issued-fixed-didnt-tell-anyone\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116","name":"Peter James","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","caption":"Peter James"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/04\/skype.png","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-Hw","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/2698"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=2698"}],"version-history":[{"count":0,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/2698\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/2496"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=2698"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=2698"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=2698"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}