CVE-2003-0502: Critical severity Apple Darwin Streaming Server vulnerability
Published Jul 25, 2003
·Updated
Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0421.
Affected Software
1 affected component
Apple Darwin Streaming Server<=4.1.3g
Event History
Jul 25, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 27, 2003
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0502?
CVE-2003-0502 is classified as a denial of service vulnerability that can crash the affected service.
2
How do I fix CVE-2003-0502?
To fix CVE-2003-0502, upgrade the affected Apple QuickTime or Darwin Streaming Server to version 4.1.3g or higher.
3
What software is affected by CVE-2003-0502?
CVE-2003-0502 affects Apple Darwin Streaming Server versions prior to 4.1.3g.
4
What type of attack is possible with CVE-2003-0502?
CVE-2003-0502 allows remote attackers to cause a denial of service through specially crafted HTTP requests.
5
When was CVE-2003-0502 disclosed?
CVE-2003-0502 was disclosed in the year 2003.