CVE-2007-6166

Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.
References
Link Resource
http://docs.info.apple.com/article.html?artnum=307176
http://lists.apple.com/archives/Security-announce/2007/Dec/msg00000.html
http://secunia.com/advisories/27755 Vendor Advisory
http://secunia.com/advisories/29182 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200803-08.xml
http://securityreason.com/securityalert/3410
http://www.beskerming.com/security/2007/11/25/74/QuickTime_-_Remote_hacker_automatic_control
http://www.kb.cert.org/vuls/id/659761 US Government Resource
http://www.securityfocus.com/bid/26549
http://www.securityfocus.com/bid/26560
http://www.securitytracker.com/id?1018989
http://www.us-cert.gov/cas/techalerts/TA07-334A.html US Government Resource
http://www.vupen.com/english/advisories/2007/3984 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/38604
https://www.exploit-db.com/exploits/4648
https://www.exploit-db.com/exploits/6013
http://docs.info.apple.com/article.html?artnum=307176
http://lists.apple.com/archives/Security-announce/2007/Dec/msg00000.html
http://secunia.com/advisories/27755 Vendor Advisory
http://secunia.com/advisories/29182 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200803-08.xml
http://securityreason.com/securityalert/3410
http://www.beskerming.com/security/2007/11/25/74/QuickTime_-_Remote_hacker_automatic_control
http://www.kb.cert.org/vuls/id/659761 US Government Resource
http://www.securityfocus.com/bid/26549
http://www.securityfocus.com/bid/26560
http://www.securitytracker.com/id?1018989
http://www.us-cert.gov/cas/techalerts/TA07-334A.html US Government Resource
http://www.vupen.com/english/advisories/2007/3984 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/38604
https://www.exploit-db.com/exploits/4648
https://www.exploit-db.com/exploits/6013
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:-:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:3.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:5.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.5.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.6:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.2:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.3:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.5:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.6:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.7:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.8:*:*:*:*:*:*:*

History

21 Nov 2024, 00:39

Type Values Removed Values Added
References () http://docs.info.apple.com/article.html?artnum=307176 - () http://docs.info.apple.com/article.html?artnum=307176 -
References () http://lists.apple.com/archives/Security-announce/2007/Dec/msg00000.html - () http://lists.apple.com/archives/Security-announce/2007/Dec/msg00000.html -
References () http://secunia.com/advisories/27755 - Vendor Advisory () http://secunia.com/advisories/27755 - Vendor Advisory
References () http://secunia.com/advisories/29182 - Vendor Advisory () http://secunia.com/advisories/29182 - Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-200803-08.xml - () http://security.gentoo.org/glsa/glsa-200803-08.xml -
References () http://securityreason.com/securityalert/3410 - () http://securityreason.com/securityalert/3410 -
References () http://www.beskerming.com/security/2007/11/25/74/QuickTime_-_Remote_hacker_automatic_control - () http://www.beskerming.com/security/2007/11/25/74/QuickTime_-_Remote_hacker_automatic_control -
References () http://www.kb.cert.org/vuls/id/659761 - US Government Resource () http://www.kb.cert.org/vuls/id/659761 - US Government Resource
References () http://www.securityfocus.com/bid/26549 - () http://www.securityfocus.com/bid/26549 -
References () http://www.securityfocus.com/bid/26560 - () http://www.securityfocus.com/bid/26560 -
References () http://www.securitytracker.com/id?1018989 - () http://www.securitytracker.com/id?1018989 -
References () http://www.us-cert.gov/cas/techalerts/TA07-334A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA07-334A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2007/3984 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/3984 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/38604 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/38604 -
References () https://www.exploit-db.com/exploits/4648 - () https://www.exploit-db.com/exploits/4648 -
References () https://www.exploit-db.com/exploits/6013 - () https://www.exploit-db.com/exploits/6013 -

Information

Published : 2007-11-29 01:46

Updated : 2024-11-21 00:39


NVD link : CVE-2007-6166

Mitre link : CVE-2007-6166

CVE.ORG link : CVE-2007-6166


JSON object : View

Products Affected

apple

  • mac_os_x
  • safari
  • quicktime

microsoft

  • windows_vista
  • windows_xp
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer