PT-2007-3516 · Apple · Apple Quicktime

Dino A. Dai Zovi

·

Published

2007-04-24

·

Updated

2018-10-16

·

CVE-2007-2175

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apple QuickTime Java extensions (QTJava.dll) (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef. This can be used to modify arbitrary memory when creating QTPointerRef objects.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2175

Affected Products

Apple Quicktime