PT-2017-16730 · Red5 · Red5 Media Server

Moritz Bechler

·

Publicado

2017-06-08

·

Atualizado

2020-08-05

·

CVE-2017-5878

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Red5 Media Server versions prior to 1.0.8
Description The issue allows remote attackers to execute arbitrary code via crafted serialized Java data due to the lack of restriction on the classes for which deserialization is performed by the AMF unmarshallers.
Recommendations For versions prior to 1.0.8, update to version 1.0.8 or later to resolve the issue.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-5878

Produtos afetados

Red5 Media Server