Vulnerability Name: | CVE-2003-1091 (CCN-12054) | ||||||||
Assigned: | 2003-05-22 | ||||||||
Published: | 2003-05-22 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed ID3 tags in MP3 files. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: BUGTRAQ Type: Exploit 20030522 QuickTime/Darwin Streaming Server security issues Source: CCN Type: BugTraq Mailing List, Thu May 22 2003 - 14:11:05 CDT QuickTime/Darwin Streaming Server security issues Source: MITRE Type: CNA CVE-2003-1091 Source: CCN Type: SECTRACK ID: 1006822 Apple Darwin Streaming Server Integer Processing Flaws May Let Remote Users Execute Arbitrary Code Source: SECTRACK Type: Exploit 1006822 Source: CCN Type: US-CERT VU#148564 Apple QuickTime/Darwin Streaming Server integer overflow in MP3Broadcaster utility Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#148564 Source: CCN Type: OSVDB ID: 16002 Apple Darwin Streaming Server MP3 Broadcasting Module MP3 ID3 Tag Overflow Source: BID Type: Exploit 7660 Source: CCN Type: BID-7660 Apple QuickTime/Darwin Streaming MP3Broadcaster ID3 Tag Handling Vulnerability Source: XF Type: UNKNOWN darwin-mp3broadcaster-code-execution(12054) Source: XF Type: UNKNOWN darwin-mp3broadcaster-code-execution(12054) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |