CVE-2003-0426: Critical severity Apple Darwin Streaming Server vulnerability
The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator password and gain privileges before the real administrator.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple QuickTime / Darwin Streaming Serverto a version that resolves this vulnerability.Fixed in 4.1.3f
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0426?
CVE-2003-0426 is considered a critical vulnerability because it allows remote attackers to gain administrative privileges.
How do I fix CVE-2003-0426?
To fix CVE-2003-0426, upgrade to Apple QuickTime or Darwin Streaming Server version 4.1.3 or later.
What systems are affected by CVE-2003-0426?
CVE-2003-0426 affects installations of Apple QuickTime and Darwin Streaming Server prior to version 4.1.3f.
What actions can attackers perform due to CVE-2003-0426?
Attackers can set the administrator password and gain unauthorized privileges due to CVE-2003-0426.
Is there a workaround for CVE-2003-0426?
A potential workaround for CVE-2003-0426 is to disable the administration server until an upgrade can be applied.