CVE-2007-2393: Critical severity QuickTime Player vulnerability
Published Jul 15, 2007
·Updated
The design of QuickTime for Java in Apple Quicktime before 7.2 allows remote attackers to bypass certain security controls and write to process memory via Java applets, possibly leading to arbitrary code execution.
Affected Software
12 affected components
QuickTime Player
QuickTime Player=7.0
QuickTime Player=7.0.1
QuickTime Player=7.0.2
QuickTime Player=7.0.3
QuickTime Player=7.0.4
QuickTime Player=7.1
QuickTime Player=7.1.1
QuickTime Player=7.1.2
QuickTime Player=7.1.3
QuickTime Player=7.1.4
QuickTime Player=7.1.5
Remediation
Patch Available
Patch Available
Event History
Jul 15, 2007
CVE Published
09:30 PM
Jul 16, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2393?
CVE-2007-2393 is considered a high severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2007-2393?
To fix CVE-2007-2393, update Apple QuickTime to version 7.2 or later.
3
What types of attacks are possible due to CVE-2007-2393?
CVE-2007-2393 allows remote attackers to bypass security controls and write to process memory, potentially leading to arbitrary code execution.
4
Which versions of QuickTime are affected by CVE-2007-2393?
CVE-2007-2393 affects several versions of Apple QuickTime prior to 7.2, including versions 7.0.1 to 7.1.5.
5
Can CVE-2007-2393 be exploited through Java applets?
Yes, CVE-2007-2393 can be exploited through Java applets, allowing attackers to execute arbitrary code.