CVE-2007-6166 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 41.9% (pctl 99)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 41.92% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-11-29 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| apple | mac os x |
| apple | quicktime |
| apple | safari |
| microsoft | windows vista |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apple QuickTime (Mac OSX) - RTSP Content-Type Overflow (Metasploit) | 2010-10-09 |
| exploit-db | Apple QuickTime 7.3 - RTSP Response Header Buffer Overflow (Metasploit) | 2010-05-09 |
| exploit-db | Apple QuickTime 7.2/7.3 - RTSP Buffer Overflow | 2010-01-06 |
| exploit-db | Apple Safari / QuickTime 7.3 - RTSP Content-Type Remote Buffer Overflow | 2008-07-06 |
| exploit-db | Apple QuickTime 7.2/7.3 - RSTP Response Universal | 2007-11-27 |
| exploit-db | Apple QuickTime 7.2/7.3 (Internet Explorer 7 / Firefox / Opera) - RTSP Response Universal | 2007-11-26 |
| exploit-db | Apple QuickTime 7.2/7.3 (Windows Vista/XP) - RSTP Response Code Execution | 2007-11-24 |
| exploit-db | Apple QuickTime 7.2/7.3 - RTSP Response Remote Overwrite (SEH) | 2007-11-23 |
References
- http://docs.info.apple.com/article.html?artnum=307176
- http://lists.apple.com/archives/Security-announce/2007/Dec/msg00000.html
- http://secunia.com/advisories/27755
- http://secunia.com/advisories/29182
- http://security.gentoo.org/glsa/glsa-200803-08.xml
- http://securityreason.com/securityalert/3410
- http://www.beskerming.com/security/2007/11/25/74/QuickTime_-_Remote_hacker_automatic_control
- http://www.kb.cert.org/vuls/id/659761
- http://www.securityfocus.com/bid/26549
- http://www.securityfocus.com/bid/26560
- http://www.securitytracker.com/id?1018989
- http://www.us-cert.gov/cas/techalerts/TA07-334A.html
- http://www.vupen.com/english/advisories/2007/3984
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38604
- https://www.exploit-db.com/exploits/4648
- https://www.exploit-db.com/exploits/6013
- http://docs.info.apple.com/article.html?artnum=307176
- http://lists.apple.com/archives/Security-announce/2007/Dec/msg00000.html
- http://secunia.com/advisories/27755
- http://secunia.com/advisories/29182
→ the Explorer · watch your stack · NVD