Multiple stack-based buffer overflows in the is_command function in proxy.c in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allow remote attackers to execute arbitrary code via a long (1) cmd or (2) server value in an RTSP request.
2007-05-13T22:19:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apple | darwin_streaming_server | 4.1.2 | Yes |
Application | apple | darwin_streaming_server | 5.0.1 | Yes |
Application | apple | darwin_streaming_server | 5.5.4 | Yes |
Operating System | apple | mac_os_x_server | 10.2.8 | No |
Operating System | apple | mac_os_x_server | 10.3 | No |
Operating System | apple | mac_os_x_server | 10.3.1 | No |
Operating System | apple | mac_os_x_server | 10.3.2 | No |
Application | apple | darwin_streaming_server | 4.1.3 | Yes |