Apple QuickTime/Darwin Streaming Server Command Execution Vulnerability
BID:6954
Info
Apple QuickTime/Darwin Streaming Server Command Execution Vulnerability
| Bugtraq ID: | 6954 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0050 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | The discovery of this vulnerability has been credited to Dave G. <[email protected]>. |
| Vulnerable: |
Apple Darwin Streaming Server 4.1.2 |
| Not Vulnerable: | |
Discussion
Apple QuickTime/Darwin Streaming Server Command Execution Vulnerability
A command execution vulnerability has been discovered in the Darwin/QuickTime Streaming Servers. The vulnerability exists due to insufficient sanitization performed on some user-supplied input.
An attacker can exploit this vulnerability by submitting a specially crafted string to the parse_xml.cgi application that include malicious shell commands. These commands, when received by the Streaming Administration Servers, will be executed and may be used to compromise a vulnerable system.
A command execution vulnerability has been discovered in the Darwin/QuickTime Streaming Servers. The vulnerability exists due to insufficient sanitization performed on some user-supplied input.
An attacker can exploit this vulnerability by submitting a specially crafted string to the parse_xml.cgi application that include malicious shell commands. These commands, when received by the Streaming Administration Servers, will be executed and may be used to compromise a vulnerable system.
Exploit / POC
Apple QuickTime/Darwin Streaming Server Command Execution Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Apple QuickTime/Darwin Streaming Server Command Execution Vulnerability
Solution:
Fixes are available:
Apple Darwin Streaming Server 4.1.2
Solution:
Fixes are available:
Apple Darwin Streaming Server 4.1.2
-
Apple MacOSXServerUpdate10.2.4.dmg
http://docs.info.apple.com/article.html?artnum=70171#English
References
Apple QuickTime/Darwin Streaming Server Command Execution Vulnerability
References:
References:
- Apple Security Updates (Apple)