CVE-2003-0423: Medium severity Apple Darwin Streaming Server vulnerability
Published Jul 25, 2003
·Updated
parsexml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter.
Affected Software
1 affected component
Apple Darwin Streaming Server=4.1.3
Event History
Jul 25, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 27, 2003
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0423?
CVE-2003-0423 is considered a moderate severity vulnerability due to the potential exposure of source code.
2
How do I fix CVE-2003-0423?
To fix CVE-2003-0423, update Apple QuickTime or Darwin Streaming Server to version 4.1.3 or later.
3
What type of attack does CVE-2003-0423 enable?
CVE-2003-0423 allows remote attackers to obtain source code through manipulation of the filename parameter.
4
Which versions of Apple software are affected by CVE-2003-0423?
CVE-2003-0423 affects Apple QuickTime and Darwin Streaming Server versions before 4.1.3g.
5
Is CVE-2003-0423 exploitable without authentication?
Yes, CVE-2003-0423 can be exploited by unauthenticated remote attackers.