Overview
Apple QuickTime contains a vulnerability that may allow an attacker to pass arbitrary commands to other applications.
Description
Apple QuickTime is a media player that is available for Microsoft Windows and Apple OS X. Apple QuickTime includes browser plugins for Internet Explorer, Safari, and Netscape-compatible browsers. QuickTime includes the ability for developers to control how QuickTime movies are launched, what controls are displayed to the user, and other actions. To specify these parameters, developers can create QuickTime link (.qtl) files. QuickTime link files can be embedded in web pages and launched automatically when a user visits a website. |
Impact
By convincing a user to open a specially crafted QuickTime file, a remote, unauthenticated attacker may be able execute arbitrary commands on a vulnerable system. |
Solution
Apple has released an update to address this issue. Mozilla has released Firefox 2.0.0.7 which reduces the impact of this vulnerability. |
Restrict access to QuickTime Movies
Workarounds for administrators
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://docs.info.apple.com/article.html?artnum=306560
- http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox
- http://www.mozilla.org/security/announce/2007/mfsa2007-28.html
- http://blog.mozilla.com/security/2007/09/18/firefox-2.0.0.7-now-available/
- http://secunia.com/advisories/26881/
- http://docs.info.apple.com/article.html?artnum=305149
- http://developer.apple.com/quicktime/quicktimeintro/tools/embed2.html
- http://noscript.net/features#contentblocking
- http://noscript.net
- http://msdn2.microsoft.com/en-us/library/ms647732.aspx
- http://support.microsoft.com/kb/224816
Acknowledgements
This vulnerability was disclosed by pdp on the GNUCITIZEN website.
This document was written by Ryan Giobbi and Will Dormann.
Other Information
CVE IDs: | CVE-2007-4673 |
Severity Metric: | 35.11 |
Date Public: | 2007-09-12 |
Date First Published: | 2007-09-13 |
Date Last Updated: | 2007-10-04 13:26 UTC |
Document Revision: | 51 |