The open source Darwin Streaming Server project has been updated to
provide the following security enhancement:
Darwin Streaming Server 5.5.1
Available for: Microsoft Windows 2000/2003 Server
CVE-ID: CAN-2005-2195
Impact: Remote attackers can hang the Web Admin application in
Darwin Streaming Server for Windows 2000/2003 Server
Description: Darwin Streaming Server is distributed with a web-based
admin application that allows it to be configured through a web
browser. Version 5.5 of the Windows 2000/2003 Server distribution of
this package is vulnerable to a denial of service attack when
handling certain web requests. Version 5.5.1 addresses the problem
by adding extra checks before opening files. Other distributions of
this package, including Mac OS X and Linux, are not vulnerable to the
attack. Credit to Sowhat of ITS Security Team for reporting this
issue.