PT-2008-1589 · Lscube · Lscube Feng

Luigi Auriemma

·

Publicado

2008-01-04

·

Atualizado

2018-10-15

·

CVE-2007-6626

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LScube Feng versions 0.1.15 and earlier
Description The issue is related to multiple buffer overflows in the RTSP valid response msg function, which can be exploited by remote attackers to execute arbitrary code. This can be achieved by sending a response with a long first line, such as a long VER line, or a long second line of a response, such as a message that follows a RETURN line.
Recommendations For LScube Feng versions 0.1.15 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6626

Produtos afetados

Lscube Feng