First published: Wed Dec 31 2003(Updated: )
Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Quicktime Streaming Server | =4.1.1 | |
Apple Darwin | =4.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1414 has a moderate severity rating due to its directory traversal vulnerability allowing unauthorized file access.
To fix CVE-2003-1414, update to the latest version of Apple Darwin Streaming Server or Apple Quicktime Streaming Server that patches this vulnerability.
CVE-2003-1414 affects Apple Darwin Streaming Server version 4.1.2 and Apple Quicktime Streaming Server version 4.1.1.
An attacker can exploit CVE-2003-1414 to perform directory traversal and access arbitrary files on the server.
If updating is not an option, consider disabling the vulnerable service or restricting access to it as a temporary workaround.