漏洞信息详情
CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Darwin Streaming Server trackID值远程缓冲区溢出漏洞
- CNNVD编号:CNNVD-200705-247
- 危害等级: 超危
- CVE编号: CVE-2007-0748
- 漏洞类型: 缓冲区溢出
- 发布时间: 2007-05-13
- 威胁类型: 远程
- 更新时间: 2007-05-14
- 厂 商: CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple
- 漏洞来源: iDEFENSE
漏洞简介
Darwin Streaming Server允许通过RTP和RTSP协议跨网络向客户端传输QuickTime数据流。
在处理SETUP请求中的trackID值时存在堆溢出,如果请求中包含有多于32个值的话,就可以触发内存破坏,导致执行任意指令。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
http://docs.info.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/article.HTML?artnum=61798
参考网址
来源: VUPEN
名称: ADV-2007-1770
链接:http://www.frsirt.com/english/advisories/2007/1770
来源: SECUNIA
名称: 25193
链接:http://secunia.com/advisories/25193
来源: IDEFENSE
名称: 20070510 CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Darwin Streaming Proxy Multiple Vulnerabilities
链接:http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=533
来源: docs.info.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com
链接:http://docs.info.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/article.HTML?artnum=305495
来源: BID
名称: 23918
链接:http://www.securityfocus.com/bid/23918
来源: OSVDB
名称: 35975
链接:http://osvdb.org/35975
来源: CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple
名称: CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple-SA-2007-05-10
链接: http://lists.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/archives/Security-announce/2007/May/msg00002.HTML
来源: XF
名称: darwin-trackid-bo(34225)
链接:http://xforce.iss.net/xforce/xfdb/34225
来源: SECTRACK
名称: 1018047
链接:http://www.securitytracker.com/id?1018047
受影响实体
- CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac_os_x_server:10.3.2
- CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac_os_x_server:10.3.1
- CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac_os_x_server:10.2.8
- CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Darwin_streaming_server:4.1.2
- CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Darwin_streaming_server:5.0.1
补丁
暂无
![weinxin](http://zone.ci/zone_ci_images/zone.ci.png)
评论