Vulnerability Description
Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox "-chrome" argument. NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Quicktime | <= 7.1.5 |
| Mozilla | Firefox | <= 2.0.0.6 |
Related Weaknesses (CWE)
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
- http://secunia.com/advisories/26881PatchVendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1
- http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox
- http://www.mozilla.org/security/announce/2007/mfsa2007-28.htmlPatch
- http://www.novell.com/linux/security/advisories/2007_57_mozilla.html
- http://www.securityfocus.com/archive/1/479179/100/0/threaded
- http://www.vupen.com/english/advisories/2007/3197
- https://bugzilla.mozilla.org/show_bug.cgi?id=395942
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
- http://secunia.com/advisories/26881PatchVendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1
- http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox
- http://www.mozilla.org/security/announce/2007/mfsa2007-28.htmlPatch
FAQ
What is CVE-2007-5045?
CVE-2007-5045 is a vulnerability with a CVSS score of 9.3 (HIGH). Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via ...
How severe is CVE-2007-5045?
CVE-2007-5045 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5045?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Quicktime, Mozilla Firefox.