CVE-2007-0754: Buffer Overflow
Published May 14, 2007
·Updated
Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted Sample Table Sample Descriptor (STSD) atom size in a QuickTime movie.
Affected Software
1 affected component
QuickTime Player<=7.1.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 14, 2007
CVE Published
09:19 PM
May 15, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0754?
CVE-2007-0754 is rated as critical due to the potential for remote code execution.
2
How do I fix CVE-2007-0754?
To fix CVE-2007-0754, upgrade Apple QuickTime to version 7.1.3 or later.
3
What systems are affected by CVE-2007-0754?
CVE-2007-0754 affects Apple QuickTime versions up to and including 7.1.2.
4
What type of vulnerability is CVE-2007-0754?
CVE-2007-0754 is a heap-based buffer overflow vulnerability.
5
Can CVE-2007-0754 be exploited remotely?
Yes, CVE-2007-0754 can be exploited remotely with user assistance through specially crafted QuickTime files.