linux/unix

05/10/2007, 6:25pm, EDT

Thursday, May 10th

Apple fixes flaws in Darwin Streaming Server

Apple has released a security update to its Darwin Streaming Server, its open source project. DSS 5.5.5 fixes two security flaws, including one where a remote attacker may be able to cause an unexpected application termination or arbitrary code execution. The company said a stack buffer overflow exists in the Darwin Streaming Proxy and that by sending maliciously-crafted RTSP requests, a remote attacker can trigger the overflow, which may lead to an unexpected application termination or arbitrary code execution.

The update addresses the issue by performing additional validation of RTSP requests. The update also fixes a flaw where a remote attacker may be able to cause an unexpected application termination or arbitrary code execution due to a heap buffer overflow in the Darwin Streaming Proxy.

The DSS 5.5.5 update is available for Mac OS X, Windows, and Linux version of the software along with the updated source code.


Filed under: software
Other story tags: Linux

, , comment, del.icio.us, slashdot, digg, buzz


post a comment
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
Be the first to post comments on this story.
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Want To Sell Your Laptop? Any Condition - receive Top Cash. Get an instant quote. Free shipping www.CashForLaptops.com
Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.