FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0169

This CVE name corresponds to:

Entered Topic
2004-02-25 Darwin Streaming Server denial-of-service vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type CVE Entry
Name CVE-2004-0169

Description

QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.

References

Source Reference
APPLE APPLE-SA-2004-02-23
IDEFENSE 20040223 Darwin Streaming Server Remote Denial of Service Vulnerability
CERT-VN VU#460350
XF darwin-describe-request-dos(15291)
BID 9735
OSVDB 6826
OSVDB 6837