CVE-2007-2394: Integer Overflow
Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2394?
CVE-2007-2394 is categorized as a critical vulnerability due to its ability to allow remote attackers to execute arbitrary code.
How do I fix CVE-2007-2394?
To fix CVE-2007-2394, users should upgrade Apple QuickTime to version 7.2 or later.
What systems are affected by CVE-2007-2394?
CVE-2007-2394 affects Apple QuickTime versions prior to 7.2 on Mac OS X 10.3.9 and 10.4.9.
What type of attack is possible with CVE-2007-2394?
CVE-2007-2394 allows user-assisted remote attackers to exploit the vulnerability through specially crafted SMIL files.
Is CVE-2007-2394 still a risk for modern systems?
CVE-2007-2394 is not a risk for modern systems that have updated QuickTime to the latest versions.