CVE-2007-0715: Buffer Overflow
Published Mar 5, 2007
·Updated
Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT file.
Affected Software
10 affected components
QuickTime Player=7.0
QuickTime Player=7.0.1
QuickTime Player=7.0.2
QuickTime Player=7.0.3
QuickTime Player=7.0.4
QuickTime Player=7.1
QuickTime Player=7.1.1
QuickTime Player=7.1.2
QuickTime Player=7.1.3
QuickTime Player=7.1.4
Remediation
Patch Available
Event History
Mar 5, 2007
CVE Published
10:19 PM
Mar 6, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0715?
CVE-2007-0715 has a medium severity rating, as it can lead to denial of service and potentially allow arbitrary code execution.
2
Which versions of Apple QuickTime are affected by CVE-2007-0715?
CVE-2007-0715 affects Apple QuickTime versions 7.0 through 7.1.4.
3
How do I fix CVE-2007-0715?
To fix CVE-2007-0715, users should update to Apple QuickTime version 7.1.5 or later.
4
What type of attack is associated with CVE-2007-0715?
CVE-2007-0715 is associated with a heap-based buffer overflow attack that exploits crafted PICT files.
5
Can CVE-2007-0715 lead to remote code execution?
Yes, CVE-2007-0715 can potentially allow remote user-assisted attackers to execute arbitrary code.