PT-2006-2464 · Apple · Quicktime Streaming Server

Publicado

2006-05-12

·

Atualizado

2017-07-20

·

CVE-2006-1456

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions QuickTime Streaming Server versions 10.3.9 through 10.4.6
Description The issue is related to a buffer overflow in the QuickTime Streaming Server, which can be exploited by remote attackers through a crafted RTSP request. This request is not properly handled during message logging, allowing attackers to execute arbitrary code.
Recommendations For versions 10.3.9 through 10.4.6, consider restricting access to the RTSP endpoint until a patch is available. As a temporary workaround, disabling the logging of RTSP requests may help minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1456

Produtos afetados

Quicktime Streaming Server