First published: Mon Mar 15 2004(Updated: )
QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Darwin | =4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0169 has a moderate severity level due to its potential to cause denial of service.
To fix CVE-2004-0169, you should update to the latest version of QuickTime Streaming Server available from Apple.
CVE-2004-0169 affects QuickTime Streaming Server on MacOS X versions 10.2.8 and 10.3.2.
CVE-2004-0169 can cause the QuickTime Streaming Server to crash, resulting in service disruption.
A potential workaround for CVE-2004-0169 is to restrict access to the server to trusted users only.