CVE-2004-1084: Medium severity Apple Quicktime Streaming Server vulnerability
Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1084?
CVE-2004-1084 is considered to have moderate severity as it allows remote attackers access to sensitive files.
How do I fix CVE-2004-1084?
To fix CVE-2004-1084, upgrade Apache to the version that addresses this vulnerability as recommended in the security announcements.
Which versions are affected by CVE-2004-1084?
CVE-2004-1084 affects Apache on Apple Mac OS X versions 10.2.8 and 10.3.6.
What type of access does CVE-2004-1084 allow?
CVE-2004-1084 allows remote attackers to read files and resource fork content via specific HTTP requests.
Is there a workaround for CVE-2004-1084?
A potential workaround for CVE-2004-1084 includes limiting access to sensitive files through configuration changes in Apache.