PT-2006-2464 · Apple · Quicktime Streaming Server
Published
2006-05-12
·
Updated
2017-07-20
·
CVE-2006-1456
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
QuickTime Streaming Server versions 10.3.9 through 10.4.6
Description
The issue is related to a buffer overflow in the QuickTime Streaming Server, which can be exploited by remote attackers through a crafted RTSP request. This request is not properly handled during message logging, allowing attackers to execute arbitrary code.
Recommendations
For versions 10.3.9 through 10.4.6, consider restricting access to the RTSP endpoint until a patch is available. As a temporary workaround, disabling the logging of RTSP requests may help minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quicktime Streaming Server