CVE-2007-2395: Critical severity QuickTime Player vulnerability
Published Nov 7, 2007
·Updated
Unspecified vulnerability in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a crafted image description atom in a movie file, related to "memory corruption."
Affected Software
1 affected component
QuickTime Player<=7.2
Remediation
Patch Available
Event History
Nov 7, 2007
CVE Published
11:46 PM
Nov 8, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2395?
CVE-2007-2395 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2007-2395?
To mitigate CVE-2007-2395, users should upgrade Apple QuickTime to version 7.3 or later.
3
What specific software is affected by CVE-2007-2395?
CVE-2007-2395 affects Apple QuickTime versions prior to 7.3.
4
What type of attack does CVE-2007-2395 allow?
CVE-2007-2395 allows remote attackers to execute arbitrary code through a crafted movie file.
5
What is the underlying issue of CVE-2007-2395?
CVE-2007-2395 is related to memory corruption caused by a malformed image description atom.