CVE-2007-2402: Infoleak
Published Jul 15, 2007
·Updated
QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient "access control," which allows remote attackers to obtain sensitive information (screen content) via crafted Java applets.
Affected Software
12 affected components
QuickTime Player
QuickTime Player=7.0
QuickTime Player=7.0.1
QuickTime Player=7.0.2
QuickTime Player=7.0.3
QuickTime Player=7.0.4
QuickTime Player=7.1
QuickTime Player=7.1.1
QuickTime Player=7.1.2
QuickTime Player=7.1.3
QuickTime Player=7.1.4
QuickTime Player=7.1.5
Remediation
Patch Available
Event History
Jul 15, 2007
CVE Published
09:30 PM
Jul 16, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2402?
CVE-2007-2402 is rated as a moderate severity vulnerability due to its potential for exposing sensitive information.
2
How do I fix CVE-2007-2402?
To fix CVE-2007-2402, you should upgrade to Apple QuickTime version 7.2 or later.
3
What type of attack can exploit CVE-2007-2402?
CVE-2007-2402 can be exploited through crafted Java applets to obtain sensitive screen content.
4
Which versions of Apple QuickTime are affected by CVE-2007-2402?
CVE-2007-2402 affects multiple versions of Apple QuickTime, including 7.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.1, 7.1.1, 7.1.2, 7.1.3, and 7.1.4.
5
What kind of information can be obtained through CVE-2007-2402?
CVE-2007-2402 allows remote attackers to access sensitive information, specifically screen content.