An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 10
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade liblivemedia | Nov 25, 2018 | Oct 19, 2018 |
| Freebsd | — | Upgrade liveMedia | Oct 29, 2018 | Oct 28, 2018 |
| Gentoo Linux | — | Upgrade media-plugins/live. | Jun 15, 2020 | Oct 19, 2018 |
| Suse | — | Upgrade live555-devel | Jan 18, 2019 | Oct 19, 2018 |
| Ubuntu | — | Upgrade liblivemedia50 (Ubuntu Pro)Upgrade liblivemedia62 (Ubuntu Pro) | Mar 22, 2023 | Oct 19, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub