Apple QuickTime/Darwin Streaming MP3Broadcaster ID3 Tag Handling Vulnerability
BID:7660
Info
Apple QuickTime/Darwin Streaming MP3Broadcaster ID3 Tag Handling Vulnerability
| Bugtraq ID: | 7660 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2003 12:00AM |
| Updated: | May 22 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Sir Mordred <[email protected]>. |
| Vulnerable: |
Apple Quicktime MP3 Broadcaster 0 |
| Not Vulnerable: | |
Discussion
Apple QuickTime/Darwin Streaming MP3Broadcaster ID3 Tag Handling Vulnerability
MP3Broadcaster is shipped as part of Darwin Streaming Server software.
MP3Broadcaster has been reported prone to a vulnerability when processing malicious ID3 tags. This is likely due to insufficient sanity checks performed when handling signed integer values contained within MP3 file ID3 tags.
MP3Broadcaster is shipped as part of Darwin Streaming Server software.
MP3Broadcaster has been reported prone to a vulnerability when processing malicious ID3 tags. This is likely due to insufficient sanity checks performed when handling signed integer values contained within MP3 file ID3 tags.
Solution / Fix
Apple QuickTime/Darwin Streaming MP3Broadcaster ID3 Tag Handling Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.