Apple QuickTime/Darwin Streaming Server Directory Traversal Vulnerability
BID:8258
Info
Apple QuickTime/Darwin Streaming Server Directory Traversal Vulnerability
| Bugtraq ID: | 8258 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0425 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2003 12:00AM |
| Updated: | Mar 19 2015 08:46AM |
| Credit: | Discovery is credited to Rapid7. |
| Vulnerable: |
Apple Quicktime Streaming Server 4.1.3 Apple Darwin Streaming Server 4.1.3 |
| Not Vulnerable: | |
Discussion
Apple QuickTime/Darwin Streaming Server Directory Traversal Vulnerability
It has been reported that QuickTime/Darwin Streaming Server is prone to a directory traversal vulnerability that may allow remote users to retrieve arbitrary files residing on the filesystem. This vulnerability may be possible to exploit using "/.../" sequences within the request sent to the server.
This vulnerability was reported to affect QuickTime/Darwin Streaming Server 4.1.3e and earlier on Windows.
It has been reported that QuickTime/Darwin Streaming Server is prone to a directory traversal vulnerability that may allow remote users to retrieve arbitrary files residing on the filesystem. This vulnerability may be possible to exploit using "/.../" sequences within the request sent to the server.
This vulnerability was reported to affect QuickTime/Darwin Streaming Server 4.1.3e and earlier on Windows.
Exploit / POC
Apple QuickTime/Darwin Streaming Server Directory Traversal Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.
Solution / Fix
Apple QuickTime/Darwin Streaming Server Directory Traversal Vulnerability
Solution:
This vulnerability has reportedly been fixed in QuickTime/Darwin version 4.1.3f or later. Upgrades may be obtained from http://developer.apple.com/darwin/projects/streaming/
Solution:
This vulnerability has reportedly been fixed in QuickTime/Darwin version 4.1.3f or later. Upgrades may be obtained from http://developer.apple.com/darwin/projects/streaming/
References
Apple QuickTime/Darwin Streaming Server Directory Traversal Vulnerability
References:
References:
- Darwin Streaming Server Homepage (Apple)