CVE-2007-5045: Code Injection
Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox "-chrome" argument. NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5045?
The severity of CVE-2007-5045 is critical, rated at 9.3 on the CVSS scale.
How do I fix CVE-2007-5045?
To fix CVE-2007-5045, you should apply the available patch for Apple QuickTime.
What software is affected by CVE-2007-5045?
CVE-2007-5045 affects Apple QuickTime 7.1.5 and earlier versions, along with systems running Mozilla Firefox prior to version 2.0.0.7.
What type of vulnerability is CVE-2007-5045?
CVE-2007-5045 is an argument injection vulnerability that allows remote attackers to execute arbitrary commands.
Can CVE-2007-5045 be exploited remotely?
Yes, CVE-2007-5045 can be exploited remotely by attackers via a specially crafted QuickTime Media Link (QTL) file.