Apple QuickTime/Darwin Streaming Server parse_xml.cgi Remote Path Disclosure Vulnerability
BID:6956
Info
Apple QuickTime/Darwin Streaming Server parse_xml.cgi Remote Path Disclosure Vulnerability
| Bugtraq ID: | 6956 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0051 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | The discovery of this vulnerability has been credited to Dave G. <[email protected]>. |
| Vulnerable: |
Apple Darwin Streaming Server 4.1.2 |
| Not Vulnerable: | |
Discussion
Apple QuickTime/Darwin Streaming Server parse_xml.cgi Remote Path Disclosure Vulnerability
A problem with the QuickTime Streaming Administration Server could make it possible for a remote user to gain potentially sensitive system information.
It has been reported that the 'parse_xml.cgi' application used by QuickTime Streaming Administration Server may return information to users that is sensitive in nature. Under some circumstances, it may be possible to reveal the physical path that the vulnerable server is installed too. Access to this information may aid in launching more organized attacks against system resources.
This vulnerability was originally described in BID 6932 "Multiple Remote
QuickTime/Darwin Streaming Administration Server Vulnerabilities". It is
now being assigned a separate BID.
A problem with the QuickTime Streaming Administration Server could make it possible for a remote user to gain potentially sensitive system information.
It has been reported that the 'parse_xml.cgi' application used by QuickTime Streaming Administration Server may return information to users that is sensitive in nature. Under some circumstances, it may be possible to reveal the physical path that the vulnerable server is installed too. Access to this information may aid in launching more organized attacks against system resources.
This vulnerability was originally described in BID 6932 "Multiple Remote
QuickTime/Darwin Streaming Administration Server Vulnerabilities". It is
now being assigned a separate BID.
Solution / Fix
Apple QuickTime/Darwin Streaming Server parse_xml.cgi Remote Path Disclosure Vulnerability
Solution:
Fixes are available:
Apple Darwin Streaming Server 4.1.2
Solution:
Fixes are available:
Apple Darwin Streaming Server 4.1.2
-
Apple MacOSXServerUpdate10.2.4.dmg
http://docs.info.apple.com/article.html?artnum=70171#English
References
Apple QuickTime/Darwin Streaming Server parse_xml.cgi Remote Path Disclosure Vulnerability
References:
References:
- Apple Security Updates (Apple)