ID

VAR-200303-0098


CVE

CVE-2003-0051


TITLE

Apple Quicktime/Darwin Streaming server parse_xml.cgi Remote path leak vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200303-036

DESCRIPTION

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter. Under some circumstances, it may be possible to reveal the physical path that the vulnerable server is installed too. Access to this information may aid in launching more organized attacks against system resources. This vulnerability was originally described in BID 6932 "Multiple Remote QuickTime/Darwin Streaming Administration Server Vulnerabilities". It is now being assigned a separate BID. By default, these services listen on port 1220/TCP with root user privileges. If an attacker passes NULL as the file name parameter and submits it to the parse_xml.cgi script, the script will return information including the physical path where the service program is installed, and the attacker can use this information to further attack the system

Trust: 1.26

sources: NVD: CVE-2003-0051 // BID: 6956 // VULHUB: VHN-6881

AFFECTED PRODUCTS

vendor:applemodel:darwin streaming serverscope:eqversion:4.1.2

Trust: 1.9

vendor:applemodel:quicktime streaming serverscope:eqversion:4.1.1

Trust: 1.6

sources: BID: 6956 // CNNVD: CNNVD-200303-036 // NVD: CVE-2003-0051

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2003-0051
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200303-036
value: MEDIUM

Trust: 0.6

VULHUB: VHN-6881
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2003-0051
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-6881
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-6881 // CNNVD: CNNVD-200303-036 // NVD: CVE-2003-0051

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2003-0051

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200303-036

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-200303-036

EXTERNAL IDS

db:BIDid:6956

Trust: 2.0

db:NVDid:CVE-2003-0051

Trust: 2.0

db:BUGTRAQid:20030224 QUICKTIME/DARWIN STREAMING ADMINISTRATION SERVER MULTIPLE VULNERABILITIES

Trust: 0.6

db:XFid:11402

Trust: 0.6

db:CNNVDid:CNNVD-200303-036

Trust: 0.6

db:VULHUBid:VHN-6881

Trust: 0.1

sources: VULHUB: VHN-6881 // BID: 6956 // CNNVD: CNNVD-200303-036 // NVD: CVE-2003-0051

REFERENCES

url:http://www.securityfocus.com/bid/6956

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2003/feb/25/applesa20030225macosx102.txt

Trust: 1.7

url:http://www.iss.net/security_center/static/11402.php

Trust: 1.7

url:http://marc.info/?l=bugtraq&m=104618904330226&w=2

Trust: 1.1

url:http://marc.theaimsgroup.com/?l=bugtraq&m=104618904330226&w=2

Trust: 0.6

url:http://www.info.apple.com/usen/security/security_updates.html

Trust: 0.3

url: -

Trust: 0.1

sources: VULHUB: VHN-6881 // BID: 6956 // CNNVD: CNNVD-200303-036 // NVD: CVE-2003-0051

CREDITS

Dave G.※ daveg@atstake.com※Ollie Whitehouse※ ollie@atstake.com

Trust: 0.6

sources: CNNVD: CNNVD-200303-036

SOURCES

db:VULHUBid:VHN-6881
db:BIDid:6956
db:CNNVDid:CNNVD-200303-036
db:NVDid:CVE-2003-0051

LAST UPDATE DATE

2024-08-14T12:05:04.235000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-6881date:2016-10-18T00:00:00
db:BIDid:6956date:2009-07-11T20:06:00
db:CNNVDid:CNNVD-200303-036date:2005-05-13T00:00:00
db:NVDid:CVE-2003-0051date:2016-10-18T02:28:48.733

SOURCES RELEASE DATE

db:VULHUBid:VHN-6881date:2003-03-07T00:00:00
db:BIDid:6956date:2003-02-24T00:00:00
db:CNNVDid:CNNVD-200303-036date:2003-02-24T00:00:00
db:NVDid:CVE-2003-0051date:2003-03-07T05:00:00