CVE-2007-2175
Summary
| CVE | CVE-2007-2175 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-04-24 16:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to modify arbitrary memory when creating QTPointerRef objects, as demonstrated during the "PWN 2 0WN" contest at CanSecWest 2007. |
Risk And Classification
Primary CVSS: v2.0 7.6 from [email protected]
AV:N/AC:H/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:H/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Apple QuickTime Java Bug Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| www.matasano.com/log/812/breaking-macbook-vuln-in-quicktime-affects-win32-appl... | af854a3a-2127-422b-91ae-364da2661108 | www.matasano.com | |
| Safari zero-day exploit nets $10,000 prize | The Register | af854a3a-2127-422b-91ae-364da2661108 | www.theregister.co.uk | |
| ZDI-07-023 | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| VU#420668 - Apple QuickTime for Java QTPointerRef heap memory corruption vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| About the security content of QuickTime 7.1.6 | af854a3a-2127-422b-91ae-364da2661108 | docs.info.apple.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Matasano Chargen » Hot Off The Matasano SMS Queue: CanSec Macbook Challenge Won | af854a3a-2127-422b-91ae-364da2661108 | www.matasano.com | |
| CanSecWest Applied Security Conference: Vancouver, British Columbia, Canada | af854a3a-2127-422b-91ae-364da2661108 | cansecwest.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www.osvdb.org/34178 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| APPLE-SA-2007-05-01 QuickTime 7.1.6 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.