CVE-2007-6166
Last modified
CVE-2007-6166 is a vulnerability of currently unknown severity. Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.. EPSS estimates a 41.92% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Quicktime | <= 7.3 |
| Apple | Quicktime | All versions |
| Apple | Quicktime | 3.0 |
| Apple | Quicktime | 4.1.2 |
| Apple | Quicktime | 5.0 |
| Apple | Quicktime | 5.0.1 |
| Apple | Quicktime | 5.0.2 |
| Apple | Quicktime | 6.0 |
| Apple | Quicktime | 6.1 |
| Apple | Quicktime | 6.5 |
| Apple | Quicktime | 6.5.1 |
| Apple | Quicktime | 6.5.2 |
| Apple | Quicktime | 7.0 |
| Apple | Quicktime | 7.0.1 |
| Apple | Quicktime | 7.0.2 |
| Apple | Quicktime | 7.0.3 |
| Apple | Quicktime | 7.0.4 |
| Apple | Quicktime | 7.1 |
| Apple | Quicktime | 7.1.1 |
| Apple | Quicktime | 7.1.2 |
| Apple | Quicktime | 7.1.3 |
| Apple | Quicktime | 7.1.4 |
| Apple | Quicktime | 7.1.5 |
| Apple | Quicktime | 7.1.6 |
| Apple | Quicktime | 7.2 |
| Apple | Safari | All versions |
References
- http://secunia.com/advisories/27755Vendor Advisory
- http://secunia.com/advisories/29182Vendor Advisory
- http://www.kb.cert.org/vuls/id/659761US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-334A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/3984Vendor Advisory
- http://secunia.com/advisories/27755Vendor Advisory
- http://secunia.com/advisories/29182Vendor Advisory
- http://www.kb.cert.org/vuls/id/659761US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-334A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/3984Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6166?
How severe is CVE-2007-6166?
How do I fix CVE-2007-6166?
Are you affected by CVE-2007-6166?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
