CVE-2007-6166
Summary
| CVE | CVE-2007-6166 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-11-29 01:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | 10.3.9 | All | All | All |
| Operating System | Apple | Mac Os X | 10.4.9 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.0 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.1 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.2 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.3 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.4 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.5 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.6 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.7 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.8 | All | All | All |
| Application | Apple | Quicktime | - | All | All | All |
| Application | Apple | Quicktime | 3.0 | All | All | All |
| Application | Apple | Quicktime | 4.1.2 | All | All | All |
| Application | Apple | Quicktime | 5.0 | All | All | All |
| Application | Apple | Quicktime | 5.0.1 | All | All | All |
| Application | Apple | Quicktime | 5.0.2 | All | All | All |
| Application | Apple | Quicktime | 6.0 | All | All | All |
| Application | Apple | Quicktime | 6.1 | All | All | All |
| Application | Apple | Quicktime | 6.5 | All | All | All |
| Application | Apple | Quicktime | 6.5.1 | All | All | All |
| Application | Apple | Quicktime | 6.5.2 | All | All | All |
| Application | Apple | Quicktime | 7.0 | All | All | All |
| Application | Apple | Quicktime | 7.0.1 | All | All | All |
| Application | Apple | Quicktime | 7.0.2 | All | All | All |
| Application | Apple | Quicktime | 7.0.3 | All | All | All |
| Application | Apple | Quicktime | 7.0.4 | All | All | All |
| Application | Apple | Quicktime | 7.1 | All | All | All |
| Application | Apple | Quicktime | 7.1.1 | All | All | All |
| Application | Apple | Quicktime | 7.1.2 | All | All | All |
| Application | Apple | Quicktime | 7.1.3 | All | All | All |
| Application | Apple | Quicktime | 7.1.4 | All | All | All |
| Application | Apple | Quicktime | 7.1.5 | All | All | All |
| Application | Apple | Quicktime | 7.1.6 | All | All | All |
| Application | Apple | Quicktime | 7.2 | All | All | All |
| Application | Apple | Quicktime | All | All | All | All |
| Application | Apple | Safari | All | All | All | All |
| Operating System | Microsoft | Windows Vista | All | All | All | All |
| Operating System | Microsoft | Windows Xp | All | sp2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About the security content of QuickTime 7.3.1 | af854a3a-2127-422b-91ae-364da2661108 | docs.info.apple.com | |
| SecurityReason - Apple QuickTime RTSP Content-Type header stack buffer overflow | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Gentoo update for win32codecs - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Win32 binary codecs: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| RETIRED: Apple QuickTime RTSP Response Header Content-Length Remote Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Apple QuickTime RTSP Response Header Content-Type Remote Stack Based Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| US-CERT Vulnerability Note VU#659761 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| SecurityTracker.com Archives - QuickTime Buffer Overflow in Processing RTSP Content-Type Header Values Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Apple - Lists.apple.com | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Apple QuickTime 7.2/7.3 RTSP Response Remote SEH Overwrite PoC | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Apple Safari / QuickTime 7.3 - RTSP Content-Type Remote Buffer Overflow - OSX remote Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| US-CERT Technical Cyber Security Alert TA07-334A -- Apple QuickTime RTSP Buffer Overflow | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Sûnnet Beskerming - QuickTime - Remote hacker automatic control | af854a3a-2127-422b-91ae-364da2661108 | www.beskerming.com | |
| Apple QuickTime RTSP "Content-Type" Header Buffer Overflow - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.