National Cyber-Alert System
Vulnerability Summary for CVE-2006-4965
Original release date:09/25/2006
Last revised:09/05/2008
Source:
US-CERT/NIST
Overview
Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain. NOTE: as of 20070912, this issue has been demonstrated by using instances of Components.interfaces.nsILocalFile and Components.interfaces.nsIProcess to execute arbitrary local files within Firefox and possibly Internet Explorer.
Impact
CVSS Severity (version 2.0):
Impact Subscore:
2.9
Exploitability Subscore:
10.0
CVSS Version 2 Metrics:
Access Vector: Network exploitable
Access Complexity: Low
Authentication: Not required to exploit
Impact Type:Allows unauthorized modification
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
US-CERT Vulnerability Note: VU#751808
Name: VU#751808
External Source: SECTRACK
Name: 1018687
External Source: BID
Name: 20138
External Source: BUGTRAQ
Name: 20070912 0DAY: QuickTime pwns Firefox
External Source: BUGTRAQ
Name: 20061207 New MySpace worm could be on its way
External Source: BUGTRAQ
Name: 20060920 Backdooring MP3 files (plus QuickTime issues and Cross-context Scripting)
External Source: MISC
Name: http://www.gnucitizen.org/blog/myspace-quicktime-worm-follow-up
External Source: MISC
Name: http://www.gnucitizen.org/blog/backdooring-mp3-files/
External Source: MISC
Name: http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox
External Source: VUPEN
Name: ADV-2007-3155
Type: Advisory
External Source: SREASON
Name: 1631
External Source: SECUNIA
Name: 27414
Type: Advisory
External Source: SECUNIA
Name: 22048
Type: Advisory
External Source: APPLE
Name: APPLE-SA-2007-03-05
External Source: CONFIRM
Name: http://docs.info.apple.com/article.html?artnum=305149