Apple QuickTime/Darwin Streaming Server parse_xml.cgi File Disclosure Vulnerability
BID:6990
Info
Apple QuickTime/Darwin Streaming Server parse_xml.cgi File Disclosure Vulnerability
| Bugtraq ID: | 6990 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2003 12:00AM |
| Updated: | Feb 28 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Joe Testa" <[email protected]>. |
| Vulnerable: |
Apple Quicktime Streaming Server 4.1.1 Apple Darwin Streaming Server 4.1.2 |
| Not Vulnerable: | |
Discussion
Apple QuickTime/Darwin Streaming Server parse_xml.cgi File Disclosure Vulnerability
A file retrieval vulnerability has been reported for QuickTime/Darwin Streaming Server. The vulnerability exists due to insufficient sanitization of some parameters given to the parse_xml.cgi script. Information obtained in this manner may be used by an attacker to launch more organinzed attacks against a vulnerable system.
This vulnerability was tested on SS for Microsoft Windows systems.
A file retrieval vulnerability has been reported for QuickTime/Darwin Streaming Server. The vulnerability exists due to insufficient sanitization of some parameters given to the parse_xml.cgi script. Information obtained in this manner may be used by an attacker to launch more organinzed attacks against a vulnerable system.
This vulnerability was tested on SS for Microsoft Windows systems.
Exploit / POC
Apple QuickTime/Darwin Streaming Server parse_xml.cgi File Disclosure Vulnerability
The following proof of concept was provided:
http://localhost:1220/parse_xml.cgi?filename=.../qtusers
The following proof of concept was provided:
http://localhost:1220/parse_xml.cgi?filename=.../qtusers
Solution / Fix
Apple QuickTime/Darwin Streaming Server parse_xml.cgi File Disclosure Vulnerability
Solution:
This issue has reportedly been fixed in version 4.1.3 of QuickTime/Darwin Streaming Server. This information has not been confirmed by the vendor.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This issue has reportedly been fixed in version 4.1.3 of QuickTime/Darwin Streaming Server. This information has not been confirmed by the vendor.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Apple QuickTime/Darwin Streaming Server parse_xml.cgi File Disclosure Vulnerability
References:
References: