CVE-2018-4013
CRITICALlive555_media_server 0.92 - Remote Code Execution via HTTP Packet Parsing
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2018-4013. PoCs published by r3dxpl0it, DoubleMice.
AI-analyzed exploit summary This PoC exploits a stack-based buffer overflow in LIVE555 RTSP server's HTTP packet-parsing functionality (CVE-2018-4013). It crafts a malicious HTTP request with an oversized 'Accept' header to trigger code execution via a buffer overflow in the 'lookForHeader' function.
Description
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.
Exploits (2)
This PoC exploits a stack-based buffer overflow in LIVE555 RTSP server's HTTP packet-parsing functionality (CVE-2018-4013). It crafts a malicious HTTP request with an oversized 'Accept' header to trigger code execution via a buffer overflow in the 'lookForHeader' function.
This PoC exploits CVE-2018-4013, a buffer overflow vulnerability in the HTTP header parsing of certain software. It sends a maliciously crafted HTTP request with an oversized 'Accept' header to trigger a denial-of-service (DoS) condition.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H