CVE-2004-0169: Medium severity Apple Darwin Streaming Server vulnerability
Published Mar 15, 2004
·Updated
QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.
Affected Software
1 affected component
Apple Darwin Streaming Server=4.1.3
Remediation
Patch Available
Event History
Mar 15, 2004
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0169?
CVE-2004-0169 has a moderate severity level due to its potential to cause denial of service.
2
How do I fix CVE-2004-0169?
To fix CVE-2004-0169, you should update to the latest version of QuickTime Streaming Server available from Apple.
3
What systems are affected by CVE-2004-0169?
CVE-2004-0169 affects QuickTime Streaming Server on MacOS X versions 10.2.8 and 10.3.2.
4
What impact can CVE-2004-0169 have on my system?
CVE-2004-0169 can cause the QuickTime Streaming Server to crash, resulting in service disruption.
5
Is there a workaround for CVE-2004-0169?
A potential workaround for CVE-2004-0169 is to restrict access to the server to trusted users only.