CVE-2007-5857
published 2007-12-19CVE-2007-5857: Quick Look in Apple Mac OS X 10.5.1 does not prevent a movie from accessing URLs when the movie file is previewed or if an icon is created, which might allow…
PriorityP422medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.85%
85.3th percentile
Quick Look in Apple Mac OS X 10.5.1 does not prevent a movie from accessing URLs when the movie file is previewed or if an icon is created, which might allow remote attackers to obtain sensitive information via HREFTrack.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)
bugzilla·2007-01-11·CVSS 9.3
CVE-2006-5857 [CRITICAL] CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)
CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)
Adobe informed us of several security vulnerabilities in Adobe Reader 7.0.8 and
earlier. They are releasing Adobe Reader 7.0.9 which fixes these flaws.
Discussion:
Please note that at this time we do not have an update for Adobe Acrobat Reader
on Red Hat Enterprise Linux 3. This is because the binaries supplied by Adobe
now rely on newer versions of libraries than were shipped with Red Hat
Enterprise Linux 3. We are currently working through possible solutions to this
problem.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
Bugzilla
CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)
bugzilla·2007-01-05·CVSS 9.3
CVE-2006-5857 [CRITICAL] CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)
CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)
Adobe informed us of several security vulnerabilities in Adobe Reader 7.0.8 and
earlier. They are releasing Adobe Reader 7.0.9 which fixes these flaws.
Discussion:
These flaws also affect the Adobe Reader shipped with RHEL3.
---
Lifting embargo:
http://www.adobe.com/support/security/bulletins/apsb07-01.html
---
Please note that at this time we do not have an update for Adobe Acrobat Reader
on Red Hat Enterprise Linux 3. This is because the binaries supplied by Adobe
now rely on newer versions of libraries than were shipped with Red Hat
Enterprise Linux 3. We are currently working through possible solutions to this
problem.
---
An advisory has been issued which should help the problem
described in this bug
http://docs.info.apple.com/article.html?artnum=307179http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.htmlhttp://secunia.com/advisories/28136http://securitytracker.com/id?1019106http://www.securityfocus.com/bid/26910http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlhttp://www.vupen.com/english/advisories/2007/4238https://exchange.xforce.ibmcloud.com/vulnerabilities/39106http://docs.info.apple.com/article.html?artnum=307179http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.htmlhttp://secunia.com/advisories/28136http://securitytracker.com/id?1019106http://www.securityfocus.com/bid/26910http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlhttp://www.vupen.com/english/advisories/2007/4238https://exchange.xforce.ibmcloud.com/vulnerabilities/39106
2007-12-19
Published