First published: Fri Mar 07 2003(Updated: )
Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Darwin | =4.1.2 | |
Apple QuickTime | =4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0054 has a high severity rating due to its potential for remote code execution.
To fix CVE-2003-0054, update the affected Apple Darwin Streaming Administration Server and QuickTime Streaming Server to their latest versions.
CVE-2003-0054 affects Apple Darwin Streaming Server version 4.1.2 and QuickTime Streaming Server version 4.1.1.
CVE-2003-0054 allows remote attackers to execute arbitrary code on the server through specially crafted requests.
A temporary workaround for CVE-2003-0054 is to restrict access to port 7070 to trusted IP addresses only.