PT-2006-5708 · Mozilla+2 · Firefox+2

Pdp

·

Publicado

2006-09-24

·

Atualizado

2018-10-17

·

CVE-2006-4965

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apple QuickTime version 7.1.3
Description The issue allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain. This can be used to execute arbitrary local files within browsers like Firefox and possibly Internet Explorer.
Recommendations For Apple QuickTime version 7.1.3, consider disabling the execution of JavaScript code from QTL files until a patch is available. Restrict access to resources outside of the original domain to minimize the risk of exploitation. Avoid using the qtnext parameter in QTL files with embed XML elements until the issue is resolved.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-4965

Produtos afetados

Apple Quicktime
Firefox
Internet Explorer