CVE-2007-6166

Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.
References
Link Resource
http://docs.info.apple.com/article.html?artnum=307176
http://lists.apple.com/archives/Security-announce/2007/Dec/msg00000.html
http://secunia.com/advisories/27755 Vendor Advisory
http://secunia.com/advisories/29182 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200803-08.xml
http://securityreason.com/securityalert/3410
http://www.beskerming.com/security/2007/11/25/74/QuickTime_-_Remote_hacker_automatic_control
http://www.kb.cert.org/vuls/id/659761 US Government Resource
http://www.securityfocus.com/bid/26549
http://www.securityfocus.com/bid/26560
http://www.securitytracker.com/id?1018989
http://www.us-cert.gov/cas/techalerts/TA07-334A.html US Government Resource
http://www.vupen.com/english/advisories/2007/3984 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/38604
https://www.exploit-db.com/exploits/4648
https://www.exploit-db.com/exploits/6013
http://docs.info.apple.com/article.html?artnum=307176
http://lists.apple.com/archives/Security-announce/2007/Dec/msg00000.html
http://secunia.com/advisories/27755 Vendor Advisory
http://secunia.com/advisories/29182 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200803-08.xml
http://securityreason.com/securityalert/3410
http://www.beskerming.com/security/2007/11/25/74/QuickTime_-_Remote_hacker_automatic_control
http://www.kb.cert.org/vuls/id/659761 US Government Resource
http://www.securityfocus.com/bid/26549
http://www.securityfocus.com/bid/26560
http://www.securitytracker.com/id?1018989
http://www.us-cert.gov/cas/techalerts/TA07-334A.html US Government Resource
http://www.vupen.com/english/advisories/2007/3984 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/38604
https://www.exploit-db.com/exploits/4648
https://www.exploit-db.com/exploits/6013
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:-:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:3.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:5.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.5.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.6:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.2:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.3:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.5:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.6:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.7:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.8:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-11-29 01:46

Updated : 2025-04-09 00:30


NVD link : CVE-2007-6166

Mitre link : CVE-2007-6166

CVE.ORG link : CVE-2007-6166


JSON object : View

Products Affected

apple

  • quicktime
  • safari
  • mac_os_x

microsoft

  • windows_vista
  • windows_xp
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer