Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1, a different vulnerability than CVE-2003-0421 and CVE-2003-0502.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=112126999514361&w=2 | mailing list |
http://securitytracker.com/id?1014474 | vdb entry |
http://secway.org/Advisory/AD20050713.txt | patch vendor advisory |
http://secunia.com/advisories/16056 | third party advisory |