CVE-2007-2392: Critical severity Apple iOS and macOS vulnerability
Published Jul 15, 2007
·Updated
Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via a crafted movie file that triggers memory corruption.
Affected Software
14 affected components
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.4.9
Apple QuickTime
Apple QuickTime=7.0
Apple QuickTime=7.0.1
Apple QuickTime=7.0.2
Apple QuickTime=7.0.3
Apple QuickTime=7.0.4
Apple QuickTime=7.1
Apple QuickTime=7.1.1
Apple QuickTime=7.1.2
Apple QuickTime=7.1.3
Apple QuickTime=7.1.4
Apple QuickTime=7.1.5
Remediation
Patch Available
Patch Available
Event History
Jul 15, 2007
CVE Published
09:30 PM
Data Sourced
09:30 PM
DescriptionWeaknessAffected Software
Jul 16, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2392?
CVE-2007-2392 is rated as high severity due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2007-2392?
To fix CVE-2007-2392, users should upgrade Apple QuickTime to version 7.2 or later.
3
Which systems are affected by CVE-2007-2392?
CVE-2007-2392 affects Apple QuickTime versions prior to 7.2 on Mac OS X versions 10.3.9 and 10.4.9.
4
What type of attack does CVE-2007-2392 facilitate?
CVE-2007-2392 facilitates user-assisted remote code execution attacks through crafted movie files.
5
Is CVE-2007-2392 a local or remote vulnerability?
CVE-2007-2392 is a remote vulnerability that requires user interaction to exploit.