| Vulnerability Name: | CVE-2007-0754 (CCN-34244) | ||||||||
| Assigned: | 2007-05-10 | ||||||||
| Published: | 2007-05-10 | ||||||||
| Updated: | 2018-10-16 | ||||||||
| Summary: | Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted Sample Table Sample Descriptor (STSD) atom size in a QuickTime movie. This vulnerability is addressed in the following product release: Apple, QuickTime, 7.1.3 | ||||||||
| CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2007-0754 Source: CCN Type: QuickTime 7.1.3 Update About the security content of QuickTime 7.1.3 Source: CONFIRM Type: Patch http://docs.info.apple.com/article.html?artnum=304357 Source: CCN Type: TPTI-07-07 Apple QuickTime STSD Parsing Heap Overflow Vulnerability Source: MISC Type: Patch, Vendor Advisory http://dvlabs.tippingpoint.com/advisory/TPTI-07-07 Source: SREASON Type: UNKNOWN 2703 Source: CCN Type: Apple QuickTime Web site Apple - QuickTime Source: OSVDB Type: UNKNOWN 35574 Source: CCN Type: OSVDB ID: 35574 Apple QuickTime Movie Sample Table Sample Descriptor (STSD) Parsing Overflow Source: BUGTRAQ Type: UNKNOWN 20070511 TPTI-07-07: Apple QuickTime STSD Parsing Heap Overflow Vulnerability Source: BID Type: Patch 23923 Source: CCN Type: BID-23923 Apple QuickTime MOV File STSD Heap Buffer Overflow Vulnerability Source: XF Type: UNKNOWN quicktime-stsd-bo(34244) Source: XF Type: UNKNOWN quicktime-stsd-bo(34244) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||