CVE-2007-4673: OS Command Injection
Published Oct 4, 2007
·Updated
Argument injection vulnerability in Apple QuickTime 7.2 for Windows XP SP2 and Vista allows remote attackers to execute arbitrary commands via a URL in the qtnext field in a crafted QTL file. NOTE: this issue may be related to CVE-2006-4965 or CVE-2007-5045.
Affected Software
2 affected components
QuickTime Player=7.2
QuickTime Player=7.2
Remediation
Patch Available
Event History
Oct 4, 2007
CVE Published
11:17 PM
Oct 5, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4673?
CVE-2007-4673 is considered to have a critical severity due to its ability to allow remote command execution.
2
How do I fix CVE-2007-4673?
To fix CVE-2007-4673, update Apple QuickTime to the latest version available from Apple.
3
What versions of QuickTime are affected by CVE-2007-4673?
CVE-2007-4673 affects QuickTime version 7.2 for both Windows XP SP2 and Windows Vista.
4
Can CVE-2007-4673 be exploited remotely?
Yes, CVE-2007-4673 can be exploited remotely through a specially crafted QTL file.
5
What type of vulnerability is CVE-2007-4673?
CVE-2007-4673 is classified as an argument injection vulnerability.