Apple QuickTime/Darwin Streaming Server Malicious Port Request Code Injection Vulnerability
BID:6960
Info
Apple QuickTime/Darwin Streaming Server Malicious Port Request Code Injection Vulnerability
| Bugtraq ID: | 6960 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0054 CVE-2003-0054 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2003 12:00AM |
| Updated: | Mar 19 2015 09:43AM |
| Credit: | The discovery of this vulnerability has been credited to Ollie Whitehouse from @stake. |
| Vulnerable: |
Apple Quicktime Streaming Server 4.1.1 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Darwin Streaming Server 4.1.2 |
| Not Vulnerable: | |
Discussion
Apple QuickTime/Darwin Streaming Server Malicious Port Request Code Injection Vulnerability
It has been reported that a vulnerability exists in the handling of malicious requests for streaming media in the Apple QuickTime/Darwin Streaming Server. By placing a malicious request to the streaming port of the software, an attacker could potentially execute script code in the security context of an administrator viewing logs which may contain the attacker-supplied script.
It has been reported that a vulnerability exists in the handling of malicious requests for streaming media in the Apple QuickTime/Darwin Streaming Server. By placing a malicious request to the streaming port of the software, an attacker could potentially execute script code in the security context of an administrator viewing logs which may contain the attacker-supplied script.
Exploit / POC
Apple QuickTime/Darwin Streaming Server Malicious Port Request Code Injection Vulnerability
There is no exploit required.
There is no exploit required.