CVE-2006-4965: Code Injection
Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain. NOTE: as of 20070912, this issue has been demonstrated by using instances of Components.interfaces.nsILocalFile and Components.interfaces.nsIProcess to execute arbitrary local files within Firefox and possibly Internet Explorer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4965?
CVE-2006-4965 has been classified as a high severity vulnerability that can lead to remote code execution.
How do I fix CVE-2006-4965?
To fix CVE-2006-4965, it is recommended to upgrade to a newer version of Apple QuickTime that does not contain this vulnerability.
What systems are affected by CVE-2006-4965?
CVE-2006-4965 specifically affects Apple QuickTime version 7.1.3.
What type of attack can be executed through CVE-2006-4965?
CVE-2006-4965 allows attackers to execute arbitrary JavaScript code via specially crafted QTL files.
Is CVE-2006-4965 related to any other vulnerabilities?
Yes, CVE-2006-4965 is part of a broader category of vulnerabilities related to improper handling of resource links in media files.