CVE-2003-0502

Apple QuickTime / Darwin Streaming Server <4.1.3g - DoS

Title source: llm
STIX 2.1

Description

Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0421.

References (2)

Core 2
Core References
Exploit, Vendor Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html
Third Party Advisory x_refsource_misc
http://www.rapid7.com/advisories/R7-0015.html

Scores

EPSS 0.0343
EPSS Percentile 87.7%

Details

Status published
Products (1)
apple/darwin_streaming_server < 4.1.3g
Published Aug 27, 2003
Tracked Since Feb 18, 2026