CVE-2007-0015
published 2007-01-01CVE-2007-0015: Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
PriorityP268medium6.8CVSS 2.0
AVNACMAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
48.42%
98.7th percentile
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | quicktime | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Apple Quicktime RTSP Overflow (2)"; flow:established,to_client; file.data; content:"|27|rtsp|3a|//"; nocase; isdataat:400,relative; content:!"|0a|"; within:400; content:!"|27|"; within:400; reference:cve,2007-0015; reference:bugtraq,21829; classtype:attempted-admin; sid:2003327; rev:11; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2010_07_30, cve CVE_2007_0015, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_11;)
snort
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Apple Quicktime RTSP Overflow (1)"; flow:established,to_client; file.data; content:"|22|rtsp|3a|//"; fast_pattern; nocase; isdataat:400,relative; content:!"|0a|"; within:400; content:!"|22|"; within:400; reference:cve,2007-0015; reference:bugtraq,21829; classtype:attempted-admin; sid:2003326; rev:11; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2010_07_30, cve CVE_2007_0015, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_11;)
bytes↗
\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49
- →Detect exploit delivery via .qtl files containing an oversized rtsp:// URI — the overflow is triggered when QuickTime processes a QTL file with a URI exceeding ~299 bytes in the rtsp:// field. ↗
- →Payload bad characters for this exploit include null bytes and common URL/HTML metacharacters; alphanumeric shellcode is used to bypass restrictions — scan for long alphanumeric blobs inside rtsp:// URIs in QTL files. ↗
- →Browser-based delivery embeds the malicious QTL/RTSP content in HTML served to the client; monitor HTTP responses containing both QuickTime embed tags and rtsp:// URIs longer than 400 characters. ↗
- →Heap spray technique uses 0x0c0c0c0c as the return address for browser-based exploitation; look for this value in memory or network payloads. ↗
- →The exploit payload space is 500 bytes; network signatures should flag rtsp:// URIs of 400+ bytes without newline or quote terminators (as implemented in the ET rules with isdataat:400,relative). ↗
- ·Firefox 3 and later blacklist the QuickTime plugin, limiting browser-based exploitation to older browser versions. ↗
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xpc5-5qwg-24vr: Buffer overflow in Apple QuickTime 7
ghsa_unreviewed·2022-05-01
CVE-2007-0015 [MEDIUM] GHSA-xpc5-5qwg-24vr: Buffer overflow in Apple QuickTime 7
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
VulnCheck
Apple quicktime Out-of-bounds Write
vulncheck·2007·CVSS 6.8
CVE-2007-0015 [MEDIUM] Apple quicktime Out-of-bounds Write
Apple quicktime Out-of-bounds Write
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
Affected: Apple quicktime
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://web.archive.org/web/20090323012515/http://securitylabs.websense.com/content/Alerts/3326.aspx; https://www.virusbulletin.com/virusbulletin/2010/05/exploit-kit-explosion-part-two-vectors-attack/
Suricata
ET WEB_CLIENT Apple Quicktime RTSP Overflow (2)
suricata·2010-07-30
CVE-2007-0015 ET WEB_CLIENT Apple Quicktime RTSP Overflow (2)
ET WEB_CLIENT Apple Quicktime RTSP Overflow (2)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Apple Quicktime RTSP Overflow (2)"; flow:established,to_client; file.data; content:"|27|rtsp|3a|//"; nocase; isdataat:400,relative; content:!"|0a|"; within:400; content:!"|27|"; within:400; reference:cve,2007-0015; reference:bugtraq,21829; classtype:attempted-admin; sid:2003327; rev:11; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2010_07_30, cve CVE_2007_0015, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_11;)
Suricata
ET WEB_CLIENT Apple Quicktime RTSP Overflow (1)
suricata·2010-07-30
CVE-2007-0015 ET WEB_CLIENT Apple Quicktime RTSP Overflow (1)
ET WEB_CLIENT Apple Quicktime RTSP Overflow (1)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Apple Quicktime RTSP Overflow (1)"; flow:established,to_client; file.data; content:"|22|rtsp|3a|//"; fast_pattern; nocase; isdataat:400,relative; content:!"|0a|"; within:400; content:!"|22|"; within:400; reference:cve,2007-0015; reference:bugtraq,21829; classtype:attempted-admin; sid:2003326; rev:11; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2010_07_30, cve CVE_2007_0015, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_11;)
Exploit-DB
Apple QuickTime 7.1.3 - RTSP URI Buffer Overflow (Metasploit)
exploitdb·2010-05-04
CVE-2007-0015 Apple QuickTime 7.1.3 - RTSP URI Buffer Overflow (Metasploit)
Apple QuickTime 7.1.3 - RTSP URI Buffer Overflow (Metasploit)
---
##
# $Id: apple_quicktime_rtsp.rb 9220 2010-05-04 23:09:32Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 OperatingSystems::WINDOWS,
:javascript => true,
:rank => NormalRanking, # reliable memory corruption
:vuln_test => nil,
})
def initialize(info = {})
super(update_info(info,
'Name' => 'Apple QuickTime 7.1.3 RTSP URI Buffer Overflow',
'Description' => %q{
This module exploits a buffer overflow in Apple QuickTime
7.1.3. This module was inspired by MOAB-01-01-2007.
Exploit-DB
Apple QuickTime (Windows 2000) - 'rtsp URL Handler' Remote Buffer Overflow
exploitdb·2007-01-03
CVE-2007-0015 Apple QuickTime (Windows 2000) - 'rtsp URL Handler' Remote Buffer Overflow
Apple QuickTime (Windows 2000) - 'rtsp URL Handler' Remote Buffer Overflow
---
#!/usr/bin/python
#Port bind exploit for apple quicktime rtsp vulnerability
#Tested on windows 2000 SP0 and SP4 with quicktime 7.1.3.100. Should be easy
#to port the exploit to others. All one needs to do is look for the appropriate
#jump address. Certain characters are not permitted in the shellcode.
#Alphanumeric shellcodes work fine.
#This script creates a qtl file which when clicked upon binds a shell to TCP
#port 4444. This file can be delivered through several means; HTTP, SMTP etc
#
# Winny Thomas ;-)
# Author shall bear no responsibility for any kind of screws up caused by using
# this code
import sys
#alpha numeric port bind shellcode from metasploit; binds shell to port 4444
shellcode = "\xeb\x03\x
Exploit-DB
Apple QuickTime - 'rtsp URL Handler' Remote Stack Buffer Overflow
exploitdb·2007-01-01
CVE-2007-0015 Apple QuickTime - 'rtsp URL Handler' Remote Stack Buffer Overflow
Apple QuickTime - 'rtsp URL Handler' Remote Stack Buffer Overflow
---
#!/usr/bin/ruby
# Copyright (c) LMH
# Kevin Finisterre
#
# Notes:
# Our command string is loaded on memory at a static address normally,
# but this depends on execution method and the string length. The address set in this exploit will
# be likely successful if we open the resulting QTL file directly, without having an
# instance of Quicktime running. Although, when using another method and string, you'll need
# to find the address.
# For 100% reliable exploitation you can always use the /bin/sh address,
# but that's not as a cool as having your box welcoming the new year.
# Do whatever you prefer. That said, enjoy.
#
# see http://projects.info-pull.com/moab/MOAB-01-01-2007.html
# Command string: Use whatever you like
Metasploit
Apple QuickTime 7.1.3 RTSP URI Buffer Overflow
metasploit
Apple QuickTime 7.1.3 RTSP URI Buffer Overflow
Apple QuickTime 7.1.3 RTSP URI Buffer Overflow
This module exploits a buffer overflow in Apple QuickTime 7.1.3. This module was inspired by MOAB-01-01-2007. The Browser target for this module was tested against IE 6 and Firefox 1.5.0.3 on Windows XP SP0/2; Firefox 3 blacklists the QuickTime plugin.
http://docs.info.apple.com/article.html?artnum=304989http://isc.sans.org/diary.html?storyid=2094http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.htmlhttp://lists.apple.com/archives/Security-announce/2007/Jan/msg00000.htmlhttp://projects.info-pull.com/moab/MOAB-01-01-2007.htmlhttp://secunia.com/advisories/23540http://secunia.com/blog/7/http://securitytracker.com/id?1017461http://www.kb.cert.org/vuls/id/442497http://www.osvdb.org/31023http://www.securityfocus.com/bid/21829http://www.us-cert.gov/cas/techalerts/TA07-005A.htmlhttp://www.vupen.com/english/advisories/2007/0001https://exchange.xforce.ibmcloud.com/vulnerabilities/31203https://www.exploit-db.com/exploits/3064http://docs.info.apple.com/article.html?artnum=304989http://isc.sans.org/diary.html?storyid=2094http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.htmlhttp://lists.apple.com/archives/Security-announce/2007/Jan/msg00000.htmlhttp://projects.info-pull.com/moab/MOAB-01-01-2007.htmlhttp://secunia.com/advisories/23540http://secunia.com/blog/7/http://securitytracker.com/id?1017461http://www.kb.cert.org/vuls/id/442497http://www.osvdb.org/31023http://www.securityfocus.com/bid/21829http://www.us-cert.gov/cas/techalerts/TA07-005A.htmlhttp://www.vupen.com/english/advisories/2007/0001https://exchange.xforce.ibmcloud.com/vulnerabilities/31203https://www.exploit-db.com/exploits/3064
2007-01-01
Published
Exploited in the wild