Multiple stack-based buffer overflows in the is_command function in proxy.c in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allow remote attackers to execute arbitrary code via a long (1) cmd or (2) server value in an RTSP request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Darwin_streaming_server | Apple | 4.1.2 (including) | 4.1.2 (including) |
Darwin_streaming_server | Apple | 5.0.1 (including) | 5.0.1 (including) |
Darwin_streaming_server | Apple | 5.5.4 (including) | 5.5.4 (including) |