CVE-2007-6166
Last modified
CVE-2007-6166 is a vulnerability of currently unknown severity. Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.. EPSS estimates a 41.92% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Quicktime | <= 7.3 |
| Apple | Quicktime | All versions |
| Apple | Quicktime | 3.0 |
| Apple | Quicktime | 4.1.2 |
| Apple | Quicktime | 5.0 |
| Apple | Quicktime | 5.0.1 |
| Apple | Quicktime | 5.0.2 |
| Apple | Quicktime | 6.0 |
| Apple | Quicktime | 6.1 |
| Apple | Quicktime | 6.5 |
| Apple | Quicktime | 6.5.1 |
| Apple | Quicktime | 6.5.2 |
| Apple | Quicktime | 7.0 |
| Apple | Quicktime | 7.0.1 |
| Apple | Quicktime | 7.0.2 |
| Apple | Quicktime | 7.0.3 |
| Apple | Quicktime | 7.0.4 |
| Apple | Quicktime | 7.1 |
| Apple | Quicktime | 7.1.1 |
| Apple | Quicktime | 7.1.2 |
| Apple | Quicktime | 7.1.3 |
| Apple | Quicktime | 7.1.4 |
| Apple | Quicktime | 7.1.5 |
| Apple | Quicktime | 7.1.6 |
| Apple | Quicktime | 7.2 |
| Apple | Safari | All versions |
References
- http://secunia.com/advisories/27755Vendor Advisory
- http://secunia.com/advisories/29182Vendor Advisory
- http://www.kb.cert.org/vuls/id/659761US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-334A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/3984Vendor Advisory
- http://secunia.com/advisories/27755Vendor Advisory
- http://secunia.com/advisories/29182Vendor Advisory
- http://www.kb.cert.org/vuls/id/659761US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-334A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/3984Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6166?
How severe is CVE-2007-6166?
How do I fix CVE-2007-6166?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6160Cross-site scripting (XSS) vulnerability in index.php in Til…
- CVE-2007-6161index.php in Tilde CMS 4.x and earlier allows remote attacke…
- CVE-2007-6162Cross-site scripting (XSS) vulnerability in index.php in FMD…
- CVE-2007-6163SQL injection vulnerability in admin/index2.asp in GOUAE DWD…
- CVE-2007-6164Multiple SQL injection vulnerabilities in Eurologon CMS allo…
- CVE-2007-6165Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted…
- CVE-2007-6167Untrusted search path vulnerability in yast2-core in SUSE Li…
- CVE-2007-6168SQL injection vulnerability in default.asp in VU Case Manage…
- CVE-2007-6169SQL injection vulnerability in admin/index2.asp in GOUAE DWD…
- CVE-2007-6170SQL injection vulnerability in the Call Detail Record Postgr…
- CVE-2007-6171SQL injection vulnerability in the Postgres Realtime Engine …
- CVE-2007-6172Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow r…
Are you affected by CVE-2007-6166?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
