CVE-2007-5045
published 2007-09-24CVE-2007-5045: Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote…
PriorityP336critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.45%
87.8th percentile
Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox "-chrome" argument. NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | quicktime | <= 7.1.5 | — |
| apple | quicktime | — | — |
| mozilla | firefox | <= 2.0.0.6 | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v7j6-cjp7-gqh6: Argument injection vulnerability in Apple QuickTime 7
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2007-4673 [MEDIUM] CWE-78 GHSA-v7j6-cjp7-gqh6: Argument injection vulnerability in Apple QuickTime 7
Argument injection vulnerability in Apple QuickTime 7.2 for Windows XP SP2 and Vista allows remote attackers to execute arbitrary commands via a URL in the qtnext field in a crafted QTL file. NOTE: this issue may be related to CVE-2006-4965 or CVE-2007-5045.
GHSA
GHSA-6x5g-m8wv-w9v6: Argument injection vulnerability in Apple QuickTime 7
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2007-5045 [MEDIUM] CWE-94 GHSA-6x5g-m8wv-w9v6: Argument injection vulnerability in Apple QuickTime 7
Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox "-chrome" argument. NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670.
Red Hat
CVE-2007-5045: Argument injection vulnerability in Apple QuickTime 7
vendor_redhat·CVSS 5.0
CVE-2007-5045 [MEDIUM] CVE-2007-5045: Argument injection vulnerability in Apple QuickTime 7
Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox "-chrome" argument. NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670.
Statement: Not vulnerable. These issues did not affect the versions of Firefox as shipped with Red Hat Enterprise Linux.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://secunia.com/advisories/26881http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefoxhttp://www.mozilla.org/security/announce/2007/mfsa2007-28.htmlhttp://www.novell.com/linux/security/advisories/2007_57_mozilla.htmlhttp://www.securityfocus.com/archive/1/479179/100/0/threadedhttp://www.vupen.com/english/advisories/2007/3197https://bugzilla.mozilla.org/show_bug.cgi?id=395942https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5896http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://secunia.com/advisories/26881http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefoxhttp://www.mozilla.org/security/announce/2007/mfsa2007-28.htmlhttp://www.novell.com/linux/security/advisories/2007_57_mozilla.htmlhttp://www.securityfocus.com/archive/1/479179/100/0/threadedhttp://www.vupen.com/english/advisories/2007/3197https://bugzilla.mozilla.org/show_bug.cgi?id=395942https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5896
2007-09-24
Published