CVE-2003-0054: High severity Apple Darwin Streaming Server vulnerability
Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0054?
CVE-2003-0054 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2003-0054?
To fix CVE-2003-0054, update the affected Apple Darwin Streaming Administration Server and QuickTime Streaming Server to their latest versions.
Which software is affected by CVE-2003-0054?
CVE-2003-0054 affects Apple Darwin Streaming Server version 4.1.2 and QuickTime Streaming Server version 4.1.1.
What types of attacks are possible with CVE-2003-0054?
CVE-2003-0054 allows remote attackers to execute arbitrary code on the server through specially crafted requests.
Is there a workaround for CVE-2003-0054 if I cannot update the software?
A temporary workaround for CVE-2003-0054 is to restrict access to port 7070 to trusted IP addresses only.