CVE-2007-2295: Buffer Overflow
Published Apr 26, 2007
·Updated
Heap-based buffer overflow in the JVTCompEncodeFrame function in Apple Quicktime 7.1.5 and other versions before 7.2 allows remote attackers to execute arbitrary code via a crafted H.264 MOV file.
Affected Software
6 affected components
QuickTime Player=7.1
QuickTime Player=7.1.1
QuickTime Player=7.1.2
QuickTime Player=7.1.3
QuickTime Player=7.1.4
QuickTime Player=7.1.5
Event History
Apr 26, 2007
CVE Published
08:19 PM
Apr 27, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2295?
CVE-2007-2295 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2007-2295?
To fix CVE-2007-2295, you should upgrade to Apple QuickTime version 7.2 or later.
3
What versions of QuickTime are affected by CVE-2007-2295?
CVE-2007-2295 affects Apple QuickTime versions 7.1.5, 7.1.4, 7.1.3, 7.1.2, 7.1.1, and 7.1.
4
What type of attack does CVE-2007-2295 enable?
CVE-2007-2295 enables remote attackers to execute arbitrary code through a specially crafted H.264 MOV file.
5
Is CVE-2007-2295 specific to any platform?
CVE-2007-2295 specifically affects the Apple QuickTime Player on macOS and Windows platforms.