Back
CVE-2018-4013
CRITICAL
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.
Published: Oct 19, 2018
Modified: Jun 17, 2026
CWE-787
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| live555 | live555_media_server | 0.92 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
GitHub Security Advisory GHSA-3rmx-2chr-mp38
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of...
References (10)
- http://lists.live555.com/pipermail/live-devel/2018-October/021071.html Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/11/msg00020.html Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202005-06 Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0684 Exploit, Third Party Advisory
- https://www.debian.org/security/2018/dsa-4343 Third Party Advisory
- http://lists.live555.com/pipermail/live-devel/2018-October/021071.html Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/11/msg00020.html Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202005-06 Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0684 Exploit, Third Party Advisory
- https://www.debian.org/security/2018/dsa-4343 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
9.67%
Top 5% most likely to be exploited
Threat Score
42.1 / 100
Data Sources
NVD
EPSS
GitHub