First published: Mon Aug 20 2007(Updated: )
Unspecified vulnerability in Skype allows remote attackers to cause a denial of service (server hang) via unknown vectors related to sending long URIs, as claimed to be actively exploited on 20070817 using a "call to a specific number." NOTE: this identifier is for the en.securitylab.ru disclosure. According to the vendor, this issue is separate from the "sign-on issues" that reduced Skype service on 20070817, which appears to be a site-specific problem. As of 20070821, it is not clear whether this issue is simply a symptom of the larger sign-on problem.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Skype |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4429 has been associated with a denial of service vulnerability, which can significantly disrupt Skype services.
To mitigate CVE-2007-4429, ensure that you are using the latest version of Skype, as updates typically include security patches.
Users of Skype software versions prior to the security patch release are affected by CVE-2007-4429.
CVE-2007-4429 is associated with a remote denial of service attack that exploits long URI inputs.
CVE-2007-4429 was reported on August 17, 2007, indicating active exploitation at that time.