CVE-2006-2022

Fenice < 1.10 - Remote Code Execution via RTSP URL Parsing Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2006-2022. PoCs published by Xpl017Elz, c0d3r.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Fenice OMS server (version 1.10) on Fedora Core 6 with exec-shield. It leverages ROP (Return-Oriented Programming) techniques to bypass memory protections and execute arbitrary code, specifically launching xterm with a display argument pointing to an attacker-controlled xhost IP.

Description

Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote attackers to execute arbitrary code via a long URL.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Xpl017Elz · cremotelinux
https://www.exploit-db.com/exploits/3815

This exploit targets a buffer overflow vulnerability in Fenice OMS server (version 1.10) on Fedora Core 6 with exec-shield. It leverages ROP (Return-Oriented Programming) techniques to bypass memory protections and execute arbitrary code, specifically launching xterm with a display argument pointing to an attacker-controlled xhost IP.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Fenice OMS server 1.10
No auth needed
Prerequisites: Network access to the target server on port 554 (default) · Fenice OMS server 1.10 running on Fedora Core 6 with exec-shield
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by c0d3r · cremotelinux
https://www.exploit-db.com/exploits/1717

This is a functional exploit for CVE-2006-2022, targeting a buffer overflow vulnerability in Fenice Open Media Streaming Server. It uses a metasploit-derived shellcode to achieve remote code execution via a crafted GET request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Fenice Open Media Streaming Server 1.10 and prior
No auth needed
Prerequisites: Network access to the target server · Fenice server running on port 554
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19770
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17678
Third Party Advisory x_refsource_misc
http://aluigi.altervista.org/adv/fenicex-adv.txt
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/431870/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/794
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/432002/100/0/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1491
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/436256/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26078

Scores

EPSS 0.1467
EPSS Percentile 96.2%

Details

Status published
Products (1)
ls3/fenice < 1.10
Published Apr 25, 2006
Tracked Since Feb 18, 2026