CVE-2007-0717: Integer Overflow
Published Mar 5, 2007
·Updated
Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.
Affected Software
10 affected components
QuickTime Player=7.0
QuickTime Player=7.0.1
QuickTime Player=7.0.2
QuickTime Player=7.0.3
QuickTime Player=7.0.4
QuickTime Player=7.1
QuickTime Player=7.1.1
QuickTime Player=7.1.2
QuickTime Player=7.1.3
QuickTime Player=7.1.4
Remediation
Patch Available
Event History
Mar 5, 2007
CVE Published
10:19 PM
Mar 6, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0717?
CVE-2007-0717 has a moderate severity rating due to its potential to cause denial of service and arbitrary code execution.
2
How do I fix CVE-2007-0717?
To fix CVE-2007-0717, upgrade Apple QuickTime to version 7.1.5 or later.
3
Which versions of Apple QuickTime are affected by CVE-2007-0717?
CVE-2007-0717 affects Apple QuickTime versions 7.0 through 7.1.4.
4
Can CVE-2007-0717 lead to remote code execution?
Yes, CVE-2007-0717 can potentially allow attackers to execute arbitrary code through crafted QTIF files.
5
What type of attack can exploit CVE-2007-0717?
CVE-2007-0717 can be exploited via remote user-assisted manipulation of QTIF files.