Vulnerability Description
Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0421.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Darwin Streaming Server | <= 4.1.3g |
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.htmlExploitVendor Advisory
- http://www.rapid7.com/advisories/R7-0015.html
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.htmlExploitVendor Advisory
- http://www.rapid7.com/advisories/R7-0015.html
FAQ
What is CVE-2003-0502?
CVE-2003-0502 is a vulnerability with a CVSS score of 10.0 (HIGH). Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a reque...
How severe is CVE-2003-0502?
CVE-2003-0502 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0502?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Darwin Streaming Server.