HIGH · 7.5

CVE-2003-0054

Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the...

Vulnerability Description

Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
AppleDarwin Streaming Server4.1.2
AppleQuicktime Streaming Server4.1.1

References

FAQ

What is CVE-2003-0054?

CVE-2003-0054 is a vulnerability with a CVSS score of 7.5 (HIGH). Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the...

How severe is CVE-2003-0054?

CVE-2003-0054 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2003-0054?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Darwin Streaming Server, Apple Quicktime Streaming Server.