PT-2006-5708 · Mozilla+2 · Firefox+2
Pdp
·
Publicado
2006-09-24
·
Atualizado
2018-10-17
·
CVE-2006-4965
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apple QuickTime version 7.1.3
Description
The issue allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a
qtnext parameter that identifies resources outside of the original domain. This can be used to execute arbitrary local files within browsers like Firefox and possibly Internet Explorer.Recommendations
For Apple QuickTime version 7.1.3, consider disabling the execution of JavaScript code from QTL files until a patch is available. Restrict access to resources outside of the original domain to minimize the risk of exploitation. Avoid using the
qtnext parameter in QTL files with embed XML elements until the issue is resolved.Exploit
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apple Quicktime
Firefox
Internet Explorer