CVE-2007-2397: Critical severity QuickTime Player vulnerability
Published Jul 15, 2007
·Updated
QuickTime for Java in Apple Quicktime before 7.2 does not properly check permissions, which allows remote attackers to disable security controls and execute arbitrary code via crafted Java applets.
Affected Software
12 affected components
QuickTime Player=7.0.3
QuickTime Player=7.1.5
QuickTime Player=7.0.1
QuickTime Player=7.0
QuickTime Player=7.0.2
QuickTime Player=7.0.4
QuickTime Player=7.1.2
QuickTime Player=7.1
QuickTime Player=7.1.1
QuickTime Player=7.1.4
QuickTime Player=7.1.3
QuickTime Player
Remediation
Patch Available
Patch Available
Event History
Jul 15, 2007
CVE Published
09:30 PM
Jul 16, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2397?
CVE-2007-2397 is rated as critical due to the potential exploitation allowing remote code execution.
2
How do I fix CVE-2007-2397?
To mitigate CVE-2007-2397, users should update Apple QuickTime to version 7.2 or later.
3
What versions of QuickTime are affected by CVE-2007-2397?
CVE-2007-2397 affects QuickTime versions prior to 7.2, including 7.0 through 7.1.5.
4
What types of attacks can CVE-2007-2397 facilitate?
CVE-2007-2397 can facilitate remote attackers executing arbitrary code through crafted Java applets.
5
Who is vulnerable to CVE-2007-2397?
Any user running affected versions of QuickTime, particularly on Java-enabled browsers, is vulnerable to CVE-2007-2397.