CVE-2018-4013

CRITICAL

Live555 Media Server - Out-of-Bounds Write

Title source: rule

Description

An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.

Exploits (2)

nomisec WORKING POC 15 stars
by r3dxpl0it · poc
https://github.com/r3dxpl0it/RTSPServer-Code-Execution-Vulnerability
nomisec WORKING POC 7 stars
by DoubleMice · poc
https://github.com/DoubleMice/cve-2018-4013

Scores

CVSS v3 9.8
EPSS 0.5164
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (3)
debian/debian_linux 8.0
debian/debian_linux 9.0
live555/live555_media_server 0.92
Published Oct 19, 2018
Tracked Since Feb 18, 2026