ID

VAR-200303-0101


CVE

CVE-2003-0054


TITLE

Apple QuickTime/Darwin Streaming Server Malicious Port Request Code Injection Vulnerability

Trust: 0.9

sources: BID: 6960 // CNNVD: CNNVD-200303-033

DESCRIPTION

Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser. It has been reported that a vulnerability exists in the handling of malicious requests for streaming media in the Apple QuickTime/Darwin Streaming Server. A remote attacker can execute some code with a request to port 7070 inside a parameter in the rtsp DESCRIBE method. This vulnerability will insert it into a log file and only execute code when this log is read by a browser

Trust: 1.26

sources: NVD: CVE-2003-0054 // BID: 6960 // VULHUB: VHN-6884

AFFECTED PRODUCTS

vendor:applemodel:quicktime streaming serverscope:eqversion:4.1.1

Trust: 1.9

vendor:applemodel:darwin streaming serverscope:eqversion:4.1.2

Trust: 1.9

vendor:applemodel:mac os serverscope:eqversion:x10.2.3

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.2

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2

Trust: 0.3

sources: BID: 6960 // CNNVD: CNNVD-200303-033 // NVD: CVE-2003-0054

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2003-0054
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200303-033
value: HIGH

Trust: 0.6

VULHUB: VHN-6884
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2003-0054
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-6884
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-6884 // CNNVD: CNNVD-200303-033 // NVD: CVE-2003-0054

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2003-0054

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200303-033

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-200303-033

EXTERNAL IDS

db:BIDid:6960

Trust: 2.0

db:NVDid:CVE-2003-0054

Trust: 2.0

db:CNNVDid:CNNVD-200303-033

Trust: 0.7

db:BUGTRAQid:20030224 QUICKTIME/DARWIN STREAMING ADMINISTRATION SERVER MULTIPLE VULNERABILITIES

Trust: 0.6

db:XFid:11405

Trust: 0.6

db:VULHUBid:VHN-6884

Trust: 0.1

sources: VULHUB: VHN-6884 // BID: 6960 // CNNVD: CNNVD-200303-033 // NVD: CVE-2003-0054

REFERENCES

url:http://www.securityfocus.com/bid/6960

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2003/feb/25/applesa20030225macosx102.txt

Trust: 1.7

url:http://www.iss.net/security_center/static/11405.php

Trust: 1.7

url:http://marc.info/?l=bugtraq&m=104618904330226&w=2

Trust: 1.1

url:http://marc.theaimsgroup.com/?l=bugtraq&m=104618904330226&w=2

Trust: 0.6

url:http://www.info.apple.com/usen/security/security_updates.html

Trust: 0.3

url:http://docs.info.apple.com/article.html?artnum=70171

Trust: 0.3

url: -

Trust: 0.1

sources: VULHUB: VHN-6884 // BID: 6960 // CNNVD: CNNVD-200303-033 // NVD: CVE-2003-0054

CREDITS

The discovery of this vulnerability has been credited to Ollie Whitehouse from @stake.

Trust: 0.9

sources: BID: 6960 // CNNVD: CNNVD-200303-033

SOURCES

db:VULHUBid:VHN-6884
db:BIDid:6960
db:CNNVDid:CNNVD-200303-033
db:NVDid:CVE-2003-0054

LAST UPDATE DATE

2024-08-14T12:38:56.651000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-6884date:2016-10-18T00:00:00
db:BIDid:6960date:2015-03-19T09:43:00
db:CNNVDid:CNNVD-200303-033date:2005-05-13T00:00:00
db:NVDid:CVE-2003-0054date:2016-10-18T02:28:52.343

SOURCES RELEASE DATE

db:VULHUBid:VHN-6884date:2003-03-07T00:00:00
db:BIDid:6960date:2003-02-24T00:00:00
db:CNNVDid:CNNVD-200303-033date:2003-03-07T00:00:00
db:NVDid:CVE-2003-0054date:2003-03-07T05:00:00