CVE-2007-0746: Buffer Overflow
Published Apr 24, 2007
·Updated
Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via a "crafted SIP packet when initializing an audio/video conference".
Affected Software
22 affected components
Apple iOS and macOS=10.4.3
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.4.9
Apple iOS and macOS=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.4.4
Apple Mac OS X Server=10.4.1
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.4
Apple Mac OS X Server=10.4
Apple Mac OS X Server=10.4.5
Apple iOS and macOS=10.4
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.3.9
Apple Mac OS X Server=10.4.8
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.4.8
Apple Mac OS X Server=10.4.7
Apple iOS and macOS=10.4.2
Remediation
Patch Available
Event History
Apr 24, 2007
CVE Published
05:19 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0746?
The severity of CVE-2007-0746 is considered high due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2007-0746?
To fix CVE-2007-0746, apply the latest security updates provided by Apple for affected versions of Mac OS X.
3
Which versions of Mac OS X are affected by CVE-2007-0746?
CVE-2007-0746 affects Mac OS X versions 10.3.9 through 10.4.9.
4
Can CVE-2007-0746 be exploited remotely?
Yes, CVE-2007-0746 can be exploited remotely through crafted SIP packets during audio/video conference initialization.
5
What are the consequences of a successful exploitation of CVE-2007-0746?
Successful exploitation of CVE-2007-0746 can lead to arbitrary code execution on the affected system.