CVE-2007-4674: Buffer Overflow
Published Nov 27, 2007
·Updated
An "integer arithmetic" error in Apple QuickTime 7.2 allows remote attackers to execute arbitrary code via a crafted movie file containing a movie atom with a large size value, which triggers a stack-based buffer overflow.
Affected Software
5 affected components
QuickTime Player=7.2
QuickTime Player=7.2
QuickTime Player=7.2
QuickTime Player=7.2
QuickTime Player=7.2
Remediation
Patch Available
Event History
Nov 27, 2007
CVE Published
08:46 PM
Nov 28, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4674?
CVE-2007-4674 is considered critical as it allows remote code execution through a crafted movie file.
2
How do I fix CVE-2007-4674?
To fix CVE-2007-4674, update Apple QuickTime to the latest version that addresses the integer arithmetic error.
3
What types of systems are affected by CVE-2007-4674?
CVE-2007-4674 affects Apple QuickTime 7.2 on various platforms including Mac OS X and Windows.
4
What can attackers do with CVE-2007-4674?
Attackers can execute arbitrary code on the victim's machine by exploiting the vulnerability via a specially crafted movie file.
5
When was CVE-2007-4674 discovered?
CVE-2007-4674 was discovered in 2007, highlighting a vulnerability in Apple QuickTime 7.2.