7.5
CVSSv2

CVE-2003-1091

Published: 31/12/2003 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via malformed ID3 tags in MP3 files.

Vulnerable Product Search on Vulmon Subscribe to Product

Exploits

source: wwwsecurityfocuscom/bid/7660/info MP3Broadcaster is shipped as part of Darwin Streaming Server software MP3Broadcaster has been reported prone to a vulnerability when processing malicious ID3 tags This is likely due to insufficient sanity checks performed when handling signed integer values contained within MP3 file ID3 tags ...