cbcvebase.
CVE-2007-6166
published 2007-11-29

CVE-2007-6166: Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time…

PriorityP275critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
41.92%
98.5th percentile
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.

Affected

24 ranges
VendorProductVersion rangeFixed in
applequicktime<= 7.3
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime

Detection & IOCsextracted from sources · hover to see the quote

port554
port554
commandRTSP/1.0 200 OK\r\nCSeq: 1\r\nContent-Type: <overflow buffer>\r\n
registryQuickTimeStreaming.qtx (7.3.0.70)
other0x67644297
other0x669c20eb
other0x6686284e
other0x8fe3f88c
other0x8fe042e0
  • The exploit triggers a stack buffer overflow in Apple QuickTime 7.2/7.3 via an overly long RTSP response Content-Type header; the overflow offset is 991 bytes (Windows) before the return address.
  • Payload bad characters for this exploit include null bytes, tab, LF, CR, space, and several URL-special characters; use these to tune IDS signatures.
  • The attack is delivered via a rogue RTSP server; the attacker binds port 554 and waits for a QuickTime client to connect, then sends the malicious RTSP response.
  • On Mac OS X targets, the overflow offset in the Content-Type header is 307 bytes before the return address; monitor for RTSP responses with Content-Type fields of this length containing non-printable data.
  • The exploit can also be delivered via browser (IE7, Firefox, Opera) by redirecting the browser to a malicious RTSP URL handled by the QuickTime plugin; monitor for rtsp:// URL redirections from web pages.
  • ·The Metasploit Windows module targets only QuickTime 7.3 (QuickTimeStreaming.qtx 7.3.0.70); the return address 0x67644297 is specific to that DLL version and will not work against other versions.
  • ·The Mac OS X Metasploit module (quicktime_rtsp_content_type.rb) notes the exploit does NOT work on Tiger (Mac OS X 10.4) for some targets.
  • ·CVE-2007-6238 is noted as probably a different vulnerability from CVE-2007-6166, though both affect Apple QuickTime 7.2 on Windows XP; duplicates are difficult to determine.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.