UBUNTU-CVE-2018-4013
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-4013
UBUNTU-CVE-2018-4013
Summary:
Details: An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.
References: https://ubuntu.com/security/CVE-2018-4013, http://lists.live555.com/pipermail/live-devel/2018-October/021071.html, https://talosintelligence.com/vulnerability_reports/TALOS-2018-0684, https://ubuntu.com/security/notices/USN-4853-1, https://www.cve.org/CVERecord?id=CVE-2018-4013
Affected packages
Package
Name: liblivemedia
Purl: pkg:deb/ubuntu/[email protected]+deb8u1build0.14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
