The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a space character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6933.
Vector
NETWORK
Complexity
LOW
Authentication
NONE
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL
VideoLAN VLC Media Player 0.9.4
VideoLAN VLC Media Player 0.9.5
VideoLAN VLC Media Player 0.9.6
VideoLAN VLC Media Player 0.9.8a
VideoLAN VLC Media Player 0.9.9
VideoLAN VLC Media Player 0.9.9a
VideoLAN VLC Media Player 0.9.10
VideoLAN VLC Media Player 1.0.0
VideoLAN VLC Media Player 1.0.1
VideoLAN VLC Media Player 1.0.2
VideoLAN VLC Media Player 1.0.3
videolan VLC Media Player 1.0.4
videolan VLC Media Player 1.0.5
videolan VLC Media Player 1.0.6
videolan VLC Media Player 1.1.0
Videolan Vlc media player 1.1.0 Rc1 (not an official CPE)
videolan VLC Media Player 1.1.4.1
videolan VLC Media Player 1.1.5
videolan VLC Media Player 1.1.4
videolan VLC Media Player 1.1.3
videolan VLC Media Player 1.1.2
videolan VLC Media Player 1.1.1
VideoLAN VLC Media Player 0.9.3
videolan VLC Media Player 1.1.6
VideoLAN VLC Media Player 0.9.2
VideoLAN VLC Media Player 0.9.1
VideoLAN VLC Media Player 0.9.0
VideoLAN VLC Media Player 0.8.1337
VideoLAN VLC Media Player 0.8.6i
VideoLAN VLC Media Player 0.8.6h
VideoLAN VLC Media Player 0.8.6g
VideoLAN VLC Media Player 0.8.6f
VideoLAN VLC Media Player 0.8.6e
VideoLAN VLC Media Player 0.8.6d
VideoLAN VLC Media Player 0.8.6c
VideoLAN VLC Media Player 0.8.6b
VideoLAN VLC Media Player 0.8.6a
VideoLAN VLC Media Player 0.8.6
VideoLAN VLC Media Player 0.8.5
VideoLAN VLC Media Player 0.8.4a
VideoLAN VLC Media Player 0.8.4
VideoLAN VLC Media Player 0.8.2
VideoLAN VLC Media Player 0.8.1
VideoLAN VLC Media Player 0.8.0
VideoLAN VLC Media Player 0.7.2
VideoLAN VLC Media Player 0.7.1
VideoLAN VLC Media Player 0.7.0
VideoLAN VLC Media Player 0.6.2
VideoLAN VLC Media Player 0.6.1
VideoLAN VLC Media Player 0.6.0
VideoLAN VLC Media Player 0.5.3
VideoLAN VLC Media Player 0.5.2
Videolan Vlc media player 0.5.1a (not an official CPE)
VideoLAN VLC Media Player 0.5.1
VideoLAN VLC Media Player 0.5.0
VideoLAN VLC Media Player 0.4.6
VideoLAN VLC Media Player 0.4.5
VideoLAN VLC Media Player 0.4.4
VideoLAN VLC Media Player 0.4.3-ac3
VideoLAN VLC Media Player 0.4.3
VideoLAN VLC Media Player 0.4.2
VideoLAN VLC Media Player 0.4.1
VideoLAN VLC Media Player 0.4.0
VideoLAN VLC Media Player 0.3.1
VideoLAN VLC Media Player 0.3.0
VideoLAN VLC Media Player 0.2.92
VideoLAN VLC Media Player 0.2.91
VideoLAN VLC Media Player 0.2.90
VideoLAN VLC Media Player 0.2.83
VideoLAN VLC Media Player 0.2.82
VideoLAN VLC Media Player 0.2.81
VideoLAN VLC Media Player 0.2.80
VideoLAN VLC Media Player 0.2.73
VideoLAN VLC Media Player 0.2.72
VideoLAN VLC Media Player 0.2.71
VideoLAN VLC Media Player 0.2.70
VideoLAN VLC Media Player 0.2.63
VideoLAN VLC Media Player 0.2.62
VideoLAN VLC Media Player 0.2.61
VideoLAN VLC Media Player 0.2.60
VideoLAN VLC Media Player 0.2.50
VideoLAN VLC Media Player 0.2.0
VideoLAN VLC Media Player 0.1.99i
VideoLAN VLC Media Player 0.1.99h
VideoLAN VLC Media Player 0.1.99g
VideoLAN VLC Media Player 0.1.99f
VideoLAN VLC Media Player 0.1.99e
VideoLAN VLC Media Player 0.1.99d
VideoLAN VLC Media Player 0.1.99c
VideoLAN VLC Media Player 0.1.99b
VideoLAN VLC Media Player 0.1.99a
Videolan Vlc media player - (not an official CPE)
Live555 Streaming media 2013-11-26 (not an official CPE)
videolan VLC Media Player 1.1.6.1
videolan VLC Media Player 1.1.7
videolan VLC Media Player 1.1.8
videolan VLC Media Player 1.1.9
videolan VLC Media Player 1.1.10
videolan VLC Media Player 1.1.10.1
videolan VLC Media Player 1.1.11
videolan VLC Media Player 1.1.12
videolan VLC Media Player 1.1.13
videolan VLC Media Player 2.0.0
VideoLAN VLC Media Player 2.0.1
VideoLAN VLC Media Player 2.0.2
VideoLAN VLC Media Player 2.0.3
VideoLAN VLC Media Player 2.0.4
VideoLAN VLC Media Player 2.0.5
VideoLAN VLC Media Player 2.0.6
VideoLAN VLC Media Player 2.0.7
VideoLAN VLC Media Player 2.0.8
VideoLAN VLC Media Player 2.0.9
Advisory | Patch | Confirmed | Link |
---|---|---|---|
65139 | |||
http://isecpartners.github.io/fuzzing/vulnerabilities/20... | |||
http://www.live555.com/liveMedia/public/changelog.txt |