CVE-2018-4013
CRITICAL
10.0
CVSS 3.0
Description
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Live Networks | LIVE555 Media Server | — | Version 0.92 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Stack-based buffer overflow |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.0 | cna | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
References (5)
- DSA-4343 https://www.debian.org/security/2018/dsa-4343
- [live-devel] 20181017 New LIVE555 version - fixes a potential vulnerability in the RTSP server implementation http://lists.live555.com/pipermail/live-devel/2018-October/021071.html
- [debian-lts-announce] 20181120 [SECURITY] [DLA 1582-1] liblivemedia security update https://lists.debian.org/debian-lts-announce/2018/11/msg00020.html
- GLSA-202005-06 https://security.gentoo.org/glsa/202005-06
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0684