Executive Summary

Informations
Name CVE-2007-3752 First vendor Publication 2007-09-06
Vendor Cve Last vendor Modification 2018-10-15

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 9.3 Attack Range Network
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Heap-based buffer overflow in Apple iTunes before 7.4 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted album cover art in the covr atom of an MP4/AAC file.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3752

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:17303
 
Oval ID: oval:org.mitre.oval:def:17303
Title: Heap-based buffer overflow in Apple iTunes before 7.4 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted album cover art in the covr atom of an MP4/AAC file
Description: Heap-based buffer overflow in Apple iTunes before 7.4 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted album cover art in the covr atom of an MP4/AAC file.
Family: windows Class: vulnerability
Reference(s): CVE-2007-3752
Version: 6
Platform(s): Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 8
Microsoft Windows Server 2012
Product(s): Apple iTunes
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 167

Open Source Vulnerability Database (OSVDB)

Id Description
38528 Apple iTunes MP4/AAC File covr atom Overflow

A local overflow exists in Apple iTunes. The media player fails to perform proper bounds checking on media file cover art resulting in a heap overflow. With a specially crafted file, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.

Nessus® Vulnerability Scanner

Date Description
2007-09-07 Name : The remote Windows host contains an application that is affected by a remote ...
File : itunes_7_4.nasl - Type : ACT_GATHER_INFO
2007-09-07 Name : The remote host contains an application that is affected by a code execution ...
File : itunes_7_4_banner.nasl - Type : ACT_GATHER_INFO
2007-09-07 Name : The remote Mac OS X host contains an application that is affected by a remote...
File : macosx_itunes_7_4.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
APPLE http://lists.apple.com/archives/security-announce/2007/Sep/msg00000.html
BID http://www.securityfocus.com/bid/25567
BUGTRAQ http://www.securityfocus.com/archive/1/478750/100/0/threaded
CONFIRM http://docs.info.apple.com/article.html?artnum=306404
MISC https://www.isecpartners.com/advisories/2007-005-itunes.txt
OSVDB http://osvdb.org/38528
OVAL https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
SECTRACK http://www.securitytracker.com/id?1018658
SECUNIA http://secunia.com/advisories/26725
VUPEN http://www.vupen.com/english/advisories/2007/3073
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/36485

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
Date Informations
2021-05-04 12:06:07
  • Multiple Updates
2021-04-22 01:06:39
  • Multiple Updates
2020-05-23 01:38:29
  • Multiple Updates
2020-05-23 00:20:06
  • Multiple Updates
2018-10-16 00:19:10
  • Multiple Updates
2017-11-29 12:02:26
  • Multiple Updates
2017-09-29 09:23:08
  • Multiple Updates
2017-07-29 12:02:23
  • Multiple Updates
2016-06-28 16:44:33
  • Multiple Updates
2016-04-26 16:22:06
  • Multiple Updates
2014-02-17 10:40:53
  • Multiple Updates
2013-11-04 21:20:31
  • Multiple Updates
2013-05-11 10:31:26
  • Multiple Updates