PT-2007-6952 · Live555 · Live555 Media Server

Published

2007-11-20

·

Updated

2018-10-15

·

CVE-2007-6036

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions LIVE555 Media Server versions 2007.11.01 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in a daemon crash. This is achieved by sending a short RTSP query, which causes a negative number to be used during memory allocation in the parseRTSPRequestString function.
Recommendations For LIVE555 Media Server versions 2007.11.01 and earlier, consider updating to a newer version to resolve the issue. As a temporary workaround, restrict access to the parseRTSPRequestString function to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6036

Affected Products

Live555 Media Server