Apple QuickTime Streaming Server Deadlock Denial of Service Vulnerability
BID:11138
Info
Apple QuickTime Streaming Server Deadlock Denial of Service Vulnerability
| Bugtraq ID: | 11138 |
| Class: | Unknown |
| CVE: |
CVE-2004-0825 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Announced by Apple. |
| Vulnerable: |
Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.2.8 |
| Not Vulnerable: | |
Discussion
Apple QuickTime Streaming Server Deadlock Denial of Service Vulnerability
It is reported that Apple QuickTime Streaming Server is vulnerable to a remotely exploitable denial of service attack. According to the report, remote clients can cause the process to deadlock by issuing a specific sequence of operations. This can render the service inoperable, resulting in a denial of service, until the server is restarted.
It is reported that Apple QuickTime Streaming Server is vulnerable to a remotely exploitable denial of service attack. According to the report, remote clients can cause the process to deadlock by issuing a specific sequence of operations. This can render the service inoperable, resulting in a denial of service, until the server is restarted.
Exploit / POC
Apple QuickTime Streaming Server Deadlock Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apple QuickTime Streaming Server Deadlock Denial of Service Vulnerability
Solution:
Apple has released an advisory (APPLE-SA-0024-09-07) along with fixes to address this, and many other issues. Please see the referenced advisory for further information.
Apple Mac OS X Server 10.2.8
Apple Mac OS X Server 10.3.4
Apple Mac OS X Server 10.3.5
Solution:
Apple has released an advisory (APPLE-SA-0024-09-07) along with fixes to address this, and many other issues. Please see the referenced advisory for further information.
Apple Mac OS X Server 10.2.8
-
Apple SecUpdSrvr2004-09-07Jag.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04716&plat form=osx&method=sa/SecUpdSrvr2004-09-07Jag.dmg
Apple Mac OS X Server 10.3.4
-
Apple SecUpdSrvr2004-09-07PanL.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04713&plat form=osx&method=sa/SecUpdSrvr2004-09-07PanL.dmg
Apple Mac OS X Server 10.3.5
-
Apple SecUpdSrvr2004-09-07PanM.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04714&plat form=osx&method=sa/SecUpdSrvr2004-09-07PanM.dmg
References
Apple QuickTime Streaming Server Deadlock Denial of Service Vulnerability
References:
References: