Vulnerability Description
Quick Look in Apple Mac OS X 10.5.1 does not prevent a movie from accessing URLs when the movie file is previewed or if an icon is created, which might allow remote attackers to obtain sensitive information via HREFTrack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Mac Os X | 10.5.1 |
Related Weaknesses (CWE)
References
- http://docs.info.apple.com/article.html?artnum=307179
- http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html
- http://secunia.com/advisories/28136
- http://securitytracker.com/id?1019106
- http://www.securityfocus.com/bid/26910
- http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/4238
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39106
- http://docs.info.apple.com/article.html?artnum=307179
- http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html
- http://secunia.com/advisories/28136
- http://securitytracker.com/id?1019106
- http://www.securityfocus.com/bid/26910
- http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/4238
FAQ
What is CVE-2007-5857?
CVE-2007-5857 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Quick Look in Apple Mac OS X 10.5.1 does not prevent a movie from accessing URLs when the movie file is previewed or if an icon is created, which might allow remote attackers to obtain sensitive infor...
How severe is CVE-2007-5857?
CVE-2007-5857 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5857?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X.