Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2007/May/msg00005.html | vendor advisory |
http://www.vupen.com/english/advisories/2007/1974 | vdb entry vendor advisory |
http://www.securitytracker.com/id?1018136 | vdb entry |
http://www.kb.cert.org/vuls/id/995836 | third party advisory us government resource |
http://www.osvdb.org/35576 | vdb entry |
http://secunia.com/advisories/25130 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/24221 | vdb entry |
http://secunia.com/secunia_research/2007-52/advisory/ | vendor advisory |