CVE-2004-0921: High severity Apple QuickTime vulnerability
Published Oct 28, 2004
·Updated
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.
Affected Software
35 affected components
Apple QuickTime=6.5.1
Apple QuickTime=5.0.2
Apple QuickTime=6.1
Apple QuickTime=6.5
Apple QuickTime=6.0
Apple Mac OS X Server=10.3.2
Apple iOS and macOS=10.2.5
Apple Mac OS X Server=10.2.2
Apple iOS and macOS=10.2.7
Apple iOS and macOS=10.2.8
Apple Mac OS X Server=10.2.4
Apple iOS and macOS=10.2.1
Apple Mac OS X Server=10.3.5
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.5
Apple Mac OS X Server=10.3.3
Apple Mac OS X Server=10.2.7
Apple Mac OS X Server=10.2.3
Apple iOS and macOS=10.2.4
Apple Mac OS X Server=10.3.4
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.2.2
Apple Mac OS X Server=10.2.5
Apple Mac OS X Server=10.3
Apple Mac OS X Server=10.2.6
Apple Mac OS X Server=10.2
Apple Mac OS X Server=10.2.1
Apple Mac OS X Server=10.3.1
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.2.6
Apple iOS and macOS=10.2.3
Apple Mac OS X Server=10.2.8
Apple iOS and macOS=10.2
Apple iOS and macOS=10.3
Remediation
Patch Available
Event History
Oct 28, 2004
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0921?
CVE-2004-0921 is considered a critical vulnerability due to the potential for unauthorized termination of authenticated user mounts.
2
How do I fix CVE-2004-0921?
To fix CVE-2004-0921, update your system to the latest version of Mac OS X or apply available patches from Apple.
3
Who is affected by CVE-2004-0921?
CVE-2004-0921 affects users of Mac OS X versions 10.3.x and certain versions of Apple QuickTime.
4
What systems are primarily impacted by CVE-2004-0921?
The primary systems impacted by CVE-2004-0921 include Mac OS X Server versions 10.3.x and specific QuickTime versions.
5
What types of attacks are associated with CVE-2004-0921?
CVE-2004-0921 is associated with denial of service attacks that can disrupt authenticated user sessions.