PT-2008-1592 · Lscube · Lscube Feng

Luigi Auriemma

·

Published

2008-01-04

·

Updated

2018-10-15

·

CVE-2007-6629

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions LScube Feng versions 0.1.15 and earlier
Description The issue is related to an interpretation conflict that allows remote attackers to cause a denial of service, resulting in a NULL dereference and daemon crash. This can be achieved by including a carriage-return character in the User-Agent header line. The conflict arises because the carriage-return character is considered a line delimiter when the header is split into individual lines, but it is not treated as such when the log user agent function in RTSP utils.c parses the content of the User-Agent line.
Recommendations For LScube Feng versions 0.1.15 and earlier, consider restricting or validating the User-Agent header to prevent the inclusion of carriage-return characters as a temporary workaround until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-6629

Affected Products

Lscube Feng