CVE-2018-4013 PUBLISHED

An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.

EPSS 51.64% · 97.9th percentile

Risk Scores

EPSS Score
51.64%
97.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSliblivemedia2018.02.18-1, 2017.09.12-1ubuntu1, 2017.07.18-1
Ubuntu:14.04:LTSliblivemedia0, 2013.04.30-1, 2013.10.25-1
Ubuntu:Pro:16.04:LTSliblivemedia2014.01.13-1, 2016.02.09-1, 2016.01.29-2

Timeline

References

Open in Interactive Console →